kejike Skill 库
开源 Agent Skill 收录中心
交流群
我的提交
提交收录
简体中文
简体中文
繁體中文
English
日本語
한국어
Français
Deutsch
Español
Português
Русский
Italiano
Türkçe
Tiếng Việt
Bahasa Indonesia
العربية
返回首页
Skill 全量检索
输入即筛选,按 / 快速聚焦
热门搜索
电商带货
商品图
选品
TikTok
code review
客服
文案
SKILL REGIONS
Skill 收录区域
按热度
按名称
SkillsMP 全量分类区域
展开 / 收起
区域内可上下滚动
安全
389,030
discord-user-post
SkillsMP
@openclaw
帖子 approved 消息 logged-in Discord 用户 Discord 桌面应用. 使用发布版本 announcements 其他 direct 用户-authored Discord 帖子; OpenClaw 通道发送, bots, Webhook, relays, 智能体 sessions, ar
Post an approved message as the logged-in Discord user through the Discord desktop app. Use for release announcements or other direct user-authored Discord posts; not for OpenClaw channel sends, bots, webhooks, relays, agent sessions, or ar
#security
openclaw/openclaw
Git 克隆
查看详情与安装步骤 →
安全
389,030
openclaw-ghsa-maintainer
SkillsMP
@openclaw
检查, 补丁, 校验, 发布, confirm OpenClaw GHSA 安全 advisories 私有-fork 状态.
Inspect, patch, validate, publish, or confirm OpenClaw GHSA security advisories and private-fork state.
#security
openclaw/openclaw
Git 克隆
查看详情与安装步骤 →
安全
389,030
openclaw-release-validation
SkillsMP
@openclaw
测试最新 OpenClaw main 提交隔离 OCM 文案显式地 approved in-place 网关更新, 指南结构化发布版本 feedback.
Test the latest OpenClaw main commit through an isolated OCM copy or an explicitly approved in-place gateway update, then guide structured release feedback.
#security
openclaw/openclaw
Git 克隆
查看详情与安装步骤 →
安全
389,030
parallels-discord-roundtrip
SkillsMP
@openclaw
运行 macOS Parallels smoke Discord 发送, 主机核验, 主机 reply, guest readback 验证.
Run macOS Parallels smoke with Discord send, host verification, host reply, and guest readback proof.
#security
openclaw/openclaw
Git 克隆
查看详情与安装步骤 →
安全
389,030
release-openclaw-mac
SkillsMP
@openclaw
运行 recover OpenClaw macOS 发布版本 signing, notarization, appcast, asset promotion.
Run or recover OpenClaw macOS release signing, notarization, appcast, and asset promotion.
#security
openclaw/openclaw
Git 克隆
查看详情与安装步骤 →
安全
389,030
telegram-e2e-userbot
SkillsMP
@openclaw
Prove 用户-可见 OpenClaw Telegram 行为 Telegram's 测试服务端 Convex-leased 团队 credentials; 云端硬盘真实-用户 turns 记录消息, 编辑, deletions, reactions, 类型标注, rich 内容.
Prove user-visible OpenClaw Telegram behavior on Telegram's Test Server with Convex-leased team credentials; drive real-user turns and record messages, edits, deletions, reactions, typing, or rich content.
#security
openclaw/openclaw
Git 克隆
查看详情与安装步骤 →
安全
389,030
add-model-provider
SkillsMP
@openclaw
添加线上-prove 模型提供方 non-可交互配置一个-liners, 无需 exposing credentials.
Add and live-prove a model provider with non-interactive config one-liners, without exposing credentials.
#security
openclaw/openclaw
Git 克隆
查看详情与安装步骤 →
安全
389,030
1password
SkillsMP
@openclaw
集合 up 使用 1Password CLI sign-in, 桌面集成, 读取 injecting secrets.
Set up and use 1Password CLI for sign-in, desktop integration, and reading or injecting secrets.
#security
openclaw/openclaw
Git 克隆
查看详情与安装步骤 →
安全
253,169
security-review
SkillsMP
@affaan-m
使用技能新增身份认证, handling 用户输入, 处理 secrets, 创建 API 接口, 实现 payment/sensitive 功能. 提供全面安全检查清单模式.
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
laravel-security
SkillsMP
@affaan-m
Buenas 拉取请求ácticas de seguridad en Laravel para autenticación/autorización, validación, CSRF, asignación masiva, subida de archivos, secretos, limitación de velocidad y despliegue seguro.
Buenas prácticas de seguridad en Laravel para autenticación/autorización, validación, CSRF, asignación masiva, subida de archivos, secretos, limitación de velocidad y despliegue seguro.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
quarkus-security
SkillsMP
@affaan-m
Buenas 拉取请求ácticas de seguridad en Quarkus para autenticación, autorización, JWT/OIDC, RBAC, validación de entrada, CSRF, gestión de secretos y seguridad de dependencias.
Buenas prácticas de seguridad en Quarkus para autenticación, autorización, JWT/OIDC, RBAC, validación de entrada, CSRF, gestión de secretos y seguridad de dependencias.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
security-review
SkillsMP
@affaan-m
Usar este 技能 al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear 接口 de API o implementar funcionalidades de pago/sensibles. Proporciona lista de verificación y patrones de seguridad completos.
Usar este skill al agregar autenticación, manejar entradas de usuario, trabajar con secretos, crear endpoints de API o implementar funcionalidades de pago/sensibles. Proporciona lista de verificación y patrones de seguridad completos.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
springboot-security
SkillsMP
@affaan-m
Buenas 拉取请求ácticas de Spring 安全 para autenticación/autorización, validación, CSRF, secretos, cabeceras, limitación de velocidad y seguridad de dependencias en servicios Java Spring Boot.
Buenas prácticas de Spring Security para autenticación/autorización, validación, CSRF, secretos, cabeceras, limitación de velocidad y seguridad de dependencias en servicios Java Spring Boot.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
django-security
SkillsMP
@affaan-m
Django 安全最佳实践, 身份认证, 授权, CSRF 防护, SQL injection prevention, XSS prevention, 安全部署 configurations.
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
kotlin-ktor-patterns
SkillsMP
@affaan-m
Ktor サーバーパターン(ルーティング DSL、プラグイン、認証、Koin DI、kotlinx. 序列化、WebSocket、testApplication テストを含む)。
Ktor サーバーパターン(ルーティング DSL、プラグイン、認証、Koin DI、kotlinx.serialization、WebSocket、testApplication テストを含む)。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
laravel-security
SkillsMP
@affaan-m
Laravel セキュリティベストプラクティス:認証・認可、バリデーション、CSRF、一括割当、ファイルアップロード、シークレット管理、レート制限、安全なデプロイメント
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
perl-security
SkillsMP
@affaan-m
テイントモード、入力バリデーション、安全なプロセス実行、DBIパラメータ化クエリ、网页セキュリティ(XSS/SQLi/CSRF)、perlcriticセキュリティポリシーを網羅する包括的なPerlセキュリティ。
テイントモード、入力バリデーション、安全なプロセス実行、DBIパラメータ化クエリ、Webセキュリティ(XSS/SQLi/CSRF)、perlcriticセキュリティポリシーを網羅する包括的なPerlセキュリティ。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
quarkus-security
SkillsMP
@affaan-m
Quarkus認証、認可、JWT/OIDC、RBAC、入力検証、CSRF、シークレット管理、依存関係セキュリティのセキュリティベストプラクティス。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
security-review
SkillsMP
@affaan-m
認証の追加、ユーザー入力の処理、シークレットの操作、APIエンドポイントの作成、支払い/機密機能の実装時にこのスキルを使用します。包括的なセキュリティチェックリストとパターンを提供します。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
security-scan
SkillsMP
@affaan-m
AgentShield を使用して、Claude 代码 の設定(. Claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE. md、settings. json、MCP サーバー、フック、エージェント定義をチェックします。
AgentShield を使用して、Claude Code の設定(.claude/ ディレクトリ)のセキュリティ脆弱性、設定ミス、インジェクションリスクをスキャンします。CLAUDE.md、settings.json、MCP サーバー、フック、エージェント定義をチェックします。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
springboot-security
SkillsMP
@affaan-m
Spring 安全最佳实践 authn/authz, 校验, CSRF, secrets, 请求头, 频率限制, 依赖安全 Java Spring Boot 服务.
Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
security-review
SkillsMP
@affaan-m
인증 추가, 사용자 입력 처리, 시크릿 관리, API 엔드포인트 생성, 결제/민감한 기능 구현 시 이 스킬을 사용하세요. 포괄적인 보안 체크리스트와 패턴을 제공합니다.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
laravel-security
SkillsMP
@affaan-m
Laravel 安全最佳实践 authn/authz, 校验, CSRF, mass assignment, 文件 uploads, secrets, 频率限制, 安全部署.
Laravel security best practices for authn/authz, validation, CSRF, mass assignment, file uploads, secrets, rate limiting, and secure deployment.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
quarkus-security
SkillsMP
@affaan-m
Quarkus 安全最佳实践身份认证, 授权, JWT/OIDC, RBAC, 输入校验, CSRF, secrets 管理, 依赖安全.
Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
security-review
SkillsMP
@affaan-m
Kimlik ğrulama eklerken, kullanıcı girdisi şlerken, secret'larla çalışırken, API 接口'leri oluştururken veya ödeme/hassas özellikler uygularken bu 技能' kullanın. Kapsamlı güvenlik kontrol listesi ve kalıplar sağlar.
Kimlik doğrulama eklerken, kullanıcı girdisi işlerken, secret'larla çalışırken, API endpoint'leri oluştururken veya ödeme/hassas özellikler uygularken bu skill'i kullanın. Kapsamlı güvenlik kontrol listesi ve kalıplar sağlar.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
springboot-security
SkillsMP
@affaan-m
Spring 安全最佳实践 authn/authz, 校验, CSRF, secrets, 请求头, 频率限制, 依赖安全 Java Spring Boot 服务.
Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
accessibility
SkillsMP
@affaan-m
使用 WCAG 2.2 级别 AA 标准设计、实施和审计包容性数字产品。运用此技能为网页生成语义 ARIA,并为网页和原生平台(iOS/安卓)生成无障碍特性。
使用 WCAG 2.2 Level AA 标准设计、实施和审计包容性数字产品。运用此技能为 Web 生成语义 ARIA,并为 Web 和原生平台(iOS/Android)生成无障碍特性。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
django-security
SkillsMP
@affaan-m
Django 安全最佳实践、认证、授权、CSRF 防护、SQL 注入预防、XSS 预防和安全部署配置。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
django-verification
SkillsMP
@affaan-m
Django项目的验证循环:迁移、代码检查、带覆盖率的测试、安全扫描,以及在发布或PR前的部署就绪检查。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
healthcare-phi-compliance
SkillsMP
@affaan-m
医疗应用中受保护健康信息(PHI)和个人身份信息(PII)的合规模式。涵盖数据分类、访问控制、审计追踪、加密及常见泄露途径。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
hipaa-compliance
SkillsMP
@affaan-m
针对医疗隐私和安全工作的HIPAA特定入口点。当任务明确围绕HIPAA、PHI处理、受保实体、BAA、违规态势或美国医疗合规要求时使用。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
kotlin-ktor-patterns
SkillsMP
@affaan-m
Ktor 服务器模式,包括路由 DSL、插件、身份验证、Koin DI、kotlinx. 序列化、WebSockets 和 testApplication 测试。
Ktor 服务器模式,包括路由 DSL、插件、身份验证、Koin DI、kotlinx.serialization、WebSockets 和 testApplication 测试。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
laravel-security
SkillsMP
@affaan-m
Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
nodejs-keccak256
SkillsMP
@affaan-m
防止 JavaScript 和 TypeScript 中的以太坊哈希错误。Node 的 sha3-256 是 NIST SHA3,而非以太坊 Keccak-256,会静默破坏选择器、签名、存储槽和地址推导。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
parallel-execution-optimizer
SkillsMP
@affaan-m
当用户希望通过并行工作、并发智能体、批量工具调用、隔离 worktree 或多条独立验证通道来大幅加速任务、同时不损失正确性时使用。
当用户希望通过并行工作、并发 agents、批量工具调用、隔离 worktree 或多条独立验证通道来大幅加速任务、同时不损失正确性时使用。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
repo-scan
SkillsMP
@affaan-m
用于从固定且可审查的提交安装外部仓库-扫描技能的引导指针。在运行跨栈源代码资产审计前需要安装仓库-扫描时使用;此 ECC 指针本身不执行审计。
用于从固定且可审查的提交安装外部 repo-scan 技能的引导指针。在运行跨栈源代码资产审计前需要安装 repo-scan 时使用;此 ECC 指针本身不执行审计。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
santa-method
SkillsMP
@affaan-m
具有收敛循环的多智能体对抗验证。两个独立的审查代理必须都通过,输出才能发送。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
security-review
SkillsMP
@affaan-m
在添加身份验证、处理用户输入、处理机密信息、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
springboot-security
SkillsMP
@affaan-m
Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring 安全最佳实践。
Java Spring Boot 服务中认证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全性的 Spring Security 最佳实践。
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
security-review
SkillsMP
@affaan-m
使用技能新增身份认证, handling 用户输入, 处理 secrets, 创建 API 接口, 实现 payment/sensitive 功能. 提供全面安全检查清单模式.
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
django-security
SkillsMP
@affaan-m
Django 安全最佳实践, 身份认证, 授权, CSRF 防护, SQL injection prevention, XSS prevention, 安全部署 configurations.
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
security-review
SkillsMP
@affaan-m
使用技能新增身份认证, handling 用户输入, 处理 secrets, 创建 API 接口, 实现 payment/sensitive 功能. 提供全面安全检查清单模式.
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
springboot-security
SkillsMP
@affaan-m
Spring 安全最佳实践 authn/authz, 校验, CSRF, secrets, 请求头, 频率限制, 依赖安全 Java Spring Boot 服务.
Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
django-security
SkillsMP
@affaan-m
Django 安全最佳实践, 身份认证, 授权, CSRF 防护, SQL injection prevention, XSS prevention, 安全部署 configurations. 使用评审 Django 身份认证, 授权, 输入 handling, depl
Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. Use when reviewing Django authentication, authorization, input handling, or depl
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
healthcare-phi-compliance
SkillsMP
@affaan-m
Protected 健康信息 (PHI) Personally Identifiable 信息 (PII) 合规模式医疗健康应用. 覆盖数据分类, 访问控制, 审计 trails, 加密, 通用 leak vectors. 使用代码 t
Protected Health Information (PHI) and Personally Identifiable Information (PII) compliance patterns for healthcare applications. Covers data classification, access control, audit trails, encryption, and common leak vectors. Use when code t
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
hipaa-compliance
SkillsMP
@affaan-m
HIPAA-特定 entrypoint 医疗健康隐私安全工作. 使用任务显式地 framed around HIPAA, PHI handling, covered 实体, BAAs, breach posture, US 医疗健康合规需求.
HIPAA-specific entrypoint for healthcare privacy and security work. Use when a task is explicitly framed around HIPAA, PHI handling, covered entities, BAAs, breach posture, or US healthcare compliance requirements.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
kotlin-ktor-patterns
SkillsMP
@affaan-m
Ktor 服务端模式包括路由 DSL, 插件, 身份认证, Koin DI, kotlinx. 序列化, WebSockets, testApplication testing. 使用构建 Ktor 服务端 — 路由, 插件, 认证, DI, 序列化, 测试.
Ktor server patterns including routing DSL, plugins, authentication, Koin DI, kotlinx.serialization, WebSockets, and testApplication testing. Use when building a Ktor server — routing, plugins, auth, DI, serialization, or tests.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
laravel-security
SkillsMP
@affaan-m
Laravel 安全最佳实践 — 身份认证, 授权, Eloquent 安全, CSRF, XSS prevention, API 安全, 安全部署 configurations. 使用评审 Laravel 认证, Eloquent 安全, CSRF, XSS, API 安全, 部署
Laravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations. Use when reviewing Laravel auth, Eloquent safety, CSRF, XSS, API security, or deploy
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
llm-trading-agent-security
SkillsMP
@affaan-m
安全模式自主交易智能体钱包 transaction authority. 覆盖提示词 injection, spend limits, pre-发送 simulation, 熔断 breakers, MEV 防护, 关键 handling. 使用自主智能体 holds 钱包
Security patterns for autonomous trading agents with wallet or transaction authority. Covers prompt injection, spend limits, pre-send simulation, circuit breakers, MEV protection, and key handling. Use when an autonomous agent holds wallet
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
mailtrap-email-integration
SkillsMP
@affaan-m
指南智能体 integrating transactional 邮件 sending 通过 Mailtrap's 邮件 API, 包括沙箱 testing, 域名核验, API 身份认证. 使用实现邮件-sending 功能, 调试 delivery 工单, sett
Guides agents through integrating transactional email sending via Mailtrap's Email API, including sandbox testing, domain verification, and API authentication. Use when implementing email-sending features, debugging delivery issues, or sett
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
perl-security
SkillsMP
@affaan-m
全面 Perl 安全覆盖 taint 模式, 输入校验, 安全流程执行, DBI parameterized 查询, 网页安全 (XSS/SQLi/CSRF), perlcritic 安全政策. 使用评审 Perl 输入 handling, 流程执行,
Comprehensive Perl security covering taint mode, input validation, safe process execution, DBI parameterized queries, web security (XSS/SQLi/CSRF), and perlcritic security policies. Use when reviewing Perl input handling, process execution,
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
quarkus-security
SkillsMP
@affaan-m
Quarkus 安全最佳实践身份认证, 授权, JWT/OIDC, RBAC, 输入校验, CSRF, secrets 管理, 依赖安全. 使用评审 Quarkus authn/authz, JWT OIDC, RBAC, 校验, secrets.
Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security. Use when reviewing Quarkus authn/authz, JWT or OIDC, RBAC, validation, or secrets.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
repo-scan
SkillsMP
@affaan-m
Bootstrap pointer 安装外部仓库-扫描技能 pinned, reviewable 提交. 使用仓库-扫描已安装在…之前 running cross-stack 来源-代码 asset 审计; ECC pointer perform 审计 itself.
Bootstrap pointer that installs the external repo-scan skill from a pinned, reviewable commit. Use when repo-scan must be installed before running its cross-stack source-code asset audit; this ECC pointer does not perform the audit itself.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
santa-method
SkillsMP
@affaan-m
多-智能体 adversarial 核验 convergence 循环. Two independent 评审智能体 pass 在…之前输出 ships. 使用输出清晰 two independent adversarial reviewers 在…之前 ships.
Multi-agent adversarial verification with convergence loop. Two independent review agents must both pass before output ships. Use when output must clear two independent adversarial reviewers before it ships.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
security-review
SkillsMP
@affaan-m
使用技能新增身份认证, handling 用户输入, 处理 secrets, 创建 API 接口, 实现 payment/sensitive 功能. 提供全面安全检查清单模式.
Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
安全
253,169
springboot-security
SkillsMP
@affaan-m
Spring 安全最佳实践 authn/authz, 校验, CSRF, secrets, 请求头, 频率限制, 依赖安全 Java Spring Boot 服务. 使用评审 Spring 安全 authn/authz, 校验, CSRF, secrets, 请求头,
Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services. Use when reviewing Spring Security authn/authz, validation, CSRF, secrets, headers, or
#security
affaan-m/ecc
Git 克隆
查看详情与安装步骤 →
系统管理
243,171
1password
SkillsMP
@NousResearch
集合 up op CLI, sign, 读取 inject secrets.
Set up op CLI, sign in, and read or inject secrets.
#system-admin
#security
nousresearch/hermes-agent
Git 克隆
查看详情与安装步骤 →
安全
243,171
antigravity-cli
SkillsMP
@NousResearch
Operate Antigravity CLI (agy): 插件, 认证, 沙箱.
Operate the Antigravity CLI (agy): plugins, auth, sandbox.
#security
nousresearch/hermes-agent
Git 克隆
查看详情与安装步骤 →
安全
243,171
actual-setup
SkillsMP
@NousResearch
集合 up Actual Computer (actual. inc) 推理计算 Hermes.
Set up Actual Computer (actual.inc) inference in Hermes.
#security
nousresearch/hermes-agent
Git 克隆
查看详情与安装步骤 →
安全
243,171
mcp-oauth-remote-gateway
SkillsMP
@NousResearch
手册 OAuth 远程 MCP 服务器 headless gateways.
Manual OAuth for remote MCP servers on headless gateways.
#security
nousresearch/hermes-agent
Git 克隆
查看详情与安装步骤 →
安全
243,171
blocked-page-recovery
SkillsMP
@NousResearch
使用获取 fails: 403/429, paywall, WAF, bot wall.
Use when a fetch fails: 403/429, paywall, WAF, bot wall.
#security
nousresearch/hermes-agent
Git 克隆
查看详情与安装步骤 →
安全
203,692
n8n-node-add-oauth
SkillsMP
@n8n-io
添加 OAuth2 credential 支持现有 n8n Node — 创建 credential 文件, 更新 Node, 添加测试, keeps CLI constant 同步. 使用用户说明 /Node-添加-oauth.
Add OAuth2 credential support to an existing n8n node — creates the credential file, updates the node, adds tests, and keeps the CLI constant in sync. Use when the user says /node-add-oauth.
#security
n8n-io/n8n
Git 克隆
查看详情与安装步骤 →
安全
203,692
credential-setup-with-computer-use
SkillsMP
@n8n-io
指南 n8n credential 初始化设置 Computer 使用浏览器工具. 使用用户需要 OAuth 应用, API 关键点, 客户端 IDs, 客户端 secrets, 其他 credential values 外部服务 console.
Guides n8n credential setup through Computer Use browser tools. Use when a user needs OAuth apps, API keys, client IDs, client secrets, or other credential values from an external service console.
#security
n8n-io/n8n
Git 克隆
查看详情与安装步骤 →
安全
132,003
cso
SkillsMP
@garrytan
Chief 安全 Officer 模式. (gstack)
Chief Security Officer mode. (gstack)
#security
garrytan/gstack
Git 克隆
查看详情与安装步骤 →
安全
132,003
setup-gbrain
SkillsMP
@garrytan
集合 up gbrain 编码智能体: 安装 CLI, 初始化本地 PGLite Supabase brain, register MCP, 采集按-远程 trust 政策. (gstack)
Set up gbrain for this coding agent: install the CLI, initialize a local PGLite or Supabase brain, register MCP, capture per-remote trust policy. (gstack)
#security
garrytan/gstack
Git 克隆
查看详情与安装步骤 →
安全
93,077
secure-homecore-plugin
SkillsMP
@ruvnet
评审原生注册外部 Wasm 插件 trust 边界.
Review native registration or external Wasm plugin trust boundaries.
#security
ruvnet/ruview
Git 克隆
查看详情与安装步骤 →
安全
93,077
verify
SkillsMP
@ruvnet
Prove RuView 结果真实 — 运行 deterministic SHA-256 验证 witness 打包合集 (ADR-028), lint claim MEASURED-vs-CLAIMED honesty.
Prove a RuView result is real — run the deterministic SHA-256 proof and the witness bundle (ADR-028), and lint any claim for MEASURED-vs-CLAIMED honesty.
#security
ruvnet/ruview
Git 克隆
查看详情与安装步骤 →
安全
93,077
ruview-cli-api
SkillsMP
@ruvnet
使用 RuView `wifi-densepose` CLI binary (incl. MAT scan/status/zones/survivors/alerts/export subcommands), REST API (`wifi-densepose-api`, Axum), 浏览器/WASM 构建 (`wifi-densepose-wasm`, `wifi-densepose-wasm-edge`). 使用 whe
Use the RuView `wifi-densepose` CLI binary (incl. MAT scan/status/zones/survivors/alerts/export subcommands), the REST API (`wifi-densepose-api`, Axum), and the browser/WASM build (`wifi-densepose-wasm`, `wifi-densepose-wasm-edge`). Use whe
#security
ruvnet/ruview
Git 克隆
查看详情与安装步骤 →
安全
92,889
security-and-hardening
SkillsMP
@addyosmani
Hardens 代码对照漏洞. 使用审计输入处理函数漏洞, handling 用户输入, 身份认证, 数据存储, 外部 integrations, 检查 login 流程安全对照 OWASP 顶部 Ten.
Hardens code against vulnerabilities. Use when auditing an input handler for vulnerabilities, when handling user input, authentication, data storage, or external integrations, or when checking a login flow is safe against the OWASP Top Ten.
#security
addyosmani/agent-skills
Git 克隆
查看详情与安装步骤 →
安全
82,309
blocking-io-guard
SkillsMP
@bytedance
确保异步-路径后端代码 block asyncio 事件循环 protected teeth-verified 运行时 anchor tests/blocking_io/. 使用修改后端 Python 应用/, packages/harness/deerflow/, 脚本/, running
Ensure async-path backend code that could block the asyncio event loop is protected by a teeth-verified runtime anchor in tests/blocking_io/. Use when changing backend Python under app/, packages/harness/deerflow/, or scripts/, when running
#security
bytedance/deer-flow
Git 克隆
查看详情与安装步骤 →
安全
80,494
query-netdata-agents
SkillsMP
@netdata
查询 Netdata 智能体 (parents children) directly 通过 HTTP API port 19999. 包含 bearer-词元辅助工具 mints, 缓存, transparently refreshes 按-智能体 bearer long-lived Netdata 云端词元, 自动-检测
Query Netdata Agents (parents and children) directly via their HTTP API on port 19999. Includes a bearer-token helper that mints, caches, and transparently refreshes a per-agent bearer from a long-lived Netdata Cloud token, and auto-detects
#security
netdata/netdata
Git 克隆
查看详情与安装步骤 →
安全
74,050
accessible-authentication
SkillsMP
@thedaviddias
使用评审 sign-in, sign-up, MFA, CAPTCHA, recovery, re-认证流程. Evaluate 完整身份认证路径, 包括错误处理备份方法, primary login 表单.
Use when reviewing sign-in, sign-up, MFA, CAPTCHA, recovery, and re-auth flows. Evaluate the full authentication path, including error handling and backup methods, not just the primary login form.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
74,050
form-captcha
SkillsMP
@thedaviddias
使用评审公开 HTML 表单 ( 身份认证必需 reach ) bot abuse 防护 mechanisms.
Use when reviewing public HTML forms (no authentication required to reach them) for bot and abuse protection mechanisms.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
74,050
form-https
SkillsMP
@thedaviddias
使用评审 HTML 表单, 获取/XHR 调用, 表单操作 attributes 确保数据 submitted exclusively HTTPS.
Use when reviewing HTML forms, fetch/XHR calls, and form action attributes to ensure data is submitted exclusively over HTTPS.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
74,050
http-to-https
SkillsMP
@thedaviddias
使用检查是否网页服务端配置 redirect HTTP traffic HTTPS.
Use when checking whether a web server is configured to redirect all HTTP traffic to HTTPS.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
74,050
https
SkillsMP
@thedaviddias
使用审计是否网站网页应用 serves 内容 exclusively HTTPS 有效证书.
Use when auditing whether a website or web application serves content exclusively over HTTPS with a valid certificate.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
74,050
offline-fallback
SkillsMP
@thedaviddias
使用新增 PWA 能力, 实现服务工作进程, improving experience 用户 unreliable 网络 connections.
Use when adding PWA capabilities, implementing a service worker, or improving the experience for users on unreliable network connections.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
74,050
password-field-security
SkillsMP
@thedaviddias
使用评审请求头, 表单, cookies, third-party integrations 相关安全 password 输入 fields. 校验 effective 浏览器 HTTP 行为生产环境-例如环境.
Use when reviewing headers, forms, cookies, or third-party integrations related to Secure password input fields. Validate the effective browser and HTTP behavior in a production-like environment.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
74,050
pwa-installability
SkillsMP
@thedaviddias
使用审计 PWA readiness, 新增安装提示词, 准备网页应用 submission Microsoft 存储 Google Play 通过 PWA 构建器.
Use when auditing PWA readiness, adding an install prompt, or preparing a web app for submission to Microsoft Store or Google Play via PWA Builder.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
74,050
session-cookie-flags
SkillsMP
@thedaviddias
使用评审服务端-端会话管理, 设置项 up 身份认证中间件, 审计 Cookie 配置 HTTP 响应请求头.
Use when reviewing server-side session management, setting up authentication middleware, or auditing cookie configuration in HTTP response headers.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
74,050
token-storage-security
SkillsMP
@thedaviddias
使用评审身份认证实现, 设置项 up 新建认证系统, evaluating 是否当前词元存储 approach exposes 应用 XSS-基于词元 theft.
Use when reviewing authentication implementation, setting up a new auth system, or evaluating whether the current token storage approach exposes the application to XSS-based token theft.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
74,050
x-content-type
SkillsMP
@thedaviddias
使用审计 HTTP 响应请求头网页服务端 CDN 安全 hardening.
Use when auditing HTTP response headers on any web server or CDN for security hardening.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
74,050
x-frame-options
SkillsMP
@thedaviddias
使用评审 HTTP 响应请求头 clickjacking 防护网页应用 authenticated 用户操作.
Use when reviewing HTTP response headers for clickjacking protection on any web application with authenticated user actions.
#security
thedaviddias/front-end-checklist
Git 克隆
查看详情与安装步骤 →
安全
71,554
agent-authentication
SkillsMP
@ruvnet
智能体技能身份认证 - 调用 $智能体-身份认证
Agent skill for authentication - invoke with $agent-authentication
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
71,554
agent-security-manager
SkillsMP
@ruvnet
智能体技能安全-manager - 调用 $智能体-安全-manager
Agent skill for security-manager - invoke with $agent-security-manager
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
71,554
claims
SkillsMP
@ruvnet
Claims-基于授权智能体运维. Grant, revoke, 核验权限安全多-智能体 coordination. 使用: 权限管理, 访问控制, 安全运维, 授权检查. Skip: 打开 acces
Claims-based authorization for agents and operations. Grant, revoke, and verify permissions for secure multi-agent coordination. Use when: permission management, access control, secure operations, authorization checks. Skip when: open acces
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
71,554
security-audit
SkillsMP
@ruvnet
全面安全扫描漏洞检测. 包含输入校验, 路径 traversal prevention, CVE 检测, 安全编码模式 enforcement. 使用: 身份认证实现, 授权逻辑, 支付 p
Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment p
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
71,554
wasm-agent
SkillsMP
@ruvnet
创建管理 sandboxed WASM 智能体隔离代码执行
Create and manage sandboxed WASM agents for isolated code execution
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
71,554
agntcy-status
SkillsMP
@ruvnet
Show AGNTCY/SLIM/CASA 集成状态 — 是否上游 AGNTCY 软件包已安装, transport (本地 vs SLIM) 活动, 是否 CASA enforcement 已启用. 使用用户要求 " AGNTCY 配置?", "show SLIM/CASA s
Show AGNTCY/SLIM/CASA integration status — whether upstream AGNTCY packages are installed, which transport (local vs SLIM) is active, and whether CASA enforcement is enabled. Use when the user asks "is AGNTCY configured?", "show SLIM/CASA s
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
71,554
safety-scan
SkillsMP
@ruvnet
扫描输入提示词 injection, unsafe 内容, adversarial attacks 使用 AIDefence. 使用处理不可信输入 (用户 submissions, API payloads, Webhook 数据, tool 输出) 在…之前 passing 模型 executing.
Scan inputs for prompt injection, unsafe content, and adversarial attacks using AIDefence. Use when processing untrusted input (user submissions, API payloads, webhook data, tool outputs) before passing it to a model or executing it.
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
71,554
browser-auth-flow
SkillsMP
@ruvnet
Probe site's 身份认证流程 redirect leaks, 缺失 CSRF, weak 会话 cookies, OAuth misconfiguration; 产出认证 findings. md
Probe a site's authentication flow for redirect leaks, missing CSRF, weak session cookies, and OAuth misconfiguration; produces an auth findings.md
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
71,554
browser-login
SkillsMP
@ruvnet
云端硬盘身份认证流程 once, sanitize cookies AIDefence, vault 可复用 Cookie 处理浏览器-cookies future sessions
Drive an authentication flow once, sanitize cookies through AIDefence, and vault a reusable cookie handle in browser-cookies for future sessions
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
71,554
harness-mcp-scan
SkillsMP
@ruvnet
静态安全扫描 harness's declared MCP 暴露面通过 `harness mcp-scan <path>`. 读取 `. mcp/servers. json` + `. harness/claims. json`. Pure-读取, dispatch. Exits 1 findings above `--fail-on` severity.
Static security scan of a harness's declared MCP surface via `harness mcp-scan <path>`. Reads `.mcp/servers.json` + `.harness/claims.json`. Pure-read, no dispatch. Exits 1 on findings at or above `--fail-on` severity.
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
71,554
security-scan
SkillsMP
@ruvnet
运行完整安全扫描代码库使用 Ruflo 安全工具. 使用评审 PRs 安全 regressions, 审计 auth/input-handling 代码, 在…之前生产环境部署, 用户要求安全检查 quick/standard/
Run full security scans on the codebase using Ruflo security tools. Use when reviewing PRs for security regressions, auditing auth/input-handling code, before production deploys, or when the user asks for a security check at quick/standard/
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
71,554
security-audit
SkillsMP
@ruvnet
安全扫描漏洞检测. 使用: 身份认证, 授权, 支付处理, 用户数据. Skip: 读取- 运维, 内部 tooling.
Security scanning and vulnerability detection. Use when: authentication, authorization, payment processing, user data. Skip when: read-only operations, internal tooling.
#security
ruvnet/ruflo
Git 克隆
查看详情与安装步骤 →
安全
70,888
career-ops-plugin-apify
SkillsMP
@career-ops-hq
如何扫描作业来源 Apify actor keyed 提供方.
How to scan a job source through an Apify actor as a keyed provider.
#security
career-ops-hq/career-ops
Git 克隆
查看详情与安装步骤 →
安全
68,803
review-work
SkillsMP
@code-yeongyu
帖子-实现 gate 评审: 运行手册 QA 真实暴露面 yourself, 上线 ONE gate 评审者 ( 面板) 审计 goal, constraints, 代码质量, 安全, missed 上下文, QA 证据. 使用在…之前 PR handoff
Post-implementation gate review: run manual QA on the real surface yourself, then launch ONE gate reviewer (never a panel) to audit goal, constraints, code quality, security, missed context, and QA evidence. Use before a PR handoff or when
#security
code-yeongyu/oh-my-openagent
Git 克隆
查看详情与安装步骤 →
安全
64,865
verify-ui-change-in-cloud
SkillsMP
@warpdotdev
核验用户-facing Warp 客户端变更 spawning 云端智能体 computer 使用测试 Warp. 使用用户显式地 requested computer-使用核验 accepted offer 运行, ONLY non-sandboxed environments
Verifies user-facing Warp client changes by spawning a cloud agent with computer use to test Warp. Use only when the user explicitly requested computer-use verification or accepted an offer to run it, and ONLY in non-sandboxed environments
#security
warpdotdev/warp
Git 克隆
查看详情与安装步骤 →
安全
64,803
onboard
SkillsMP
@mem0ai
集合 up mem0 新建项目包括 API 关键配置, MCP 身份认证, 项目文件导入, 编码分类. 使用首先运行新建项目, API 关键需要更新, re-运行初始初始化设置在…之后配置 c
Sets up mem0 for a new project including API key configuration, MCP authentication, project file import, and coding categories. Use on first run in a new project, when API key needs updating, or to re-run initial setup after configuration c
#security
mem0ai/mem0
Git 克隆
查看详情与安装步骤 →
安全
64,803
memory-triage
SkillsMP
@mem0ai
持久化 long-term 记忆协议 powered mem0. Evaluate 对话 durable facts worth storing 通过 memory_add. 处理 identity, preferences, 决策, configurations, 规则, 项目, relationships. Loaded opencla
Persistent long-term memory protocol powered by mem0. Evaluate conversations for durable facts worth storing via memory_add. Handles identity, preferences, decisions, configurations, rules, projects, and relationships. Loaded by the opencla
#security
mem0ai/mem0
Git 克隆
查看详情与安装步骤 →
安全
64,803
mem0-integrate
SkillsMP
@mem0ai
集成 Mem0 现有仓库使用 goal-driven, TDD 流水线. 检测仓库's 语言自动地要求用户 pick Mem0 平台 (托管) Mem0 开源 (self-hosted). 编写 failing 测试 befor
Integrate Mem0 into an existing repository using a goal-driven, TDD pipeline. Detects the repo's language automatically and asks the user to pick between Mem0 Platform (managed) and Mem0 Open Source (self-hosted). Writes failing tests befor
#security
mem0ai/mem0
Git 克隆
查看详情与安装步骤 →
安全
64,803
mem0-test-integration
SkillsMP
@mem0ai
核验 Mem0 集成产出 /mem0-集成. 运行 same 工作区 same 分支 (loose coupling) — 安装依赖, 运行仓库's 原生测试套件, exercises 真实端到端 smoke 流程对照用户's
Verify a Mem0 integration produced by /mem0-integrate. Runs in the same workspace on the same branch (loose coupling) — installs dependencies, runs the repo's native test suite, then exercises a real end-to-end smoke flow against the user's
#security
mem0ai/mem0
Git 克隆
查看详情与安装步骤 →
安全
62,007
application-security-testing
SkillsMP
@usestrix
应用安全 testing (AppSec) 跨全部商品 Strix — decide asset 需要测试 (源码, running 网页应用, API, CI 流水线), 运行, 转换结果 ranked remediation 计划. 自主智能体 e
Application security testing (AppSec) across a whole product with Strix — decide which asset needs which test (source code, running web app, API, CI pipeline), run it, and turn the results into a ranked remediation plan. Autonomous agents e
#security
usestrix/strix
Git 克隆
查看详情与安装步骤 →
安全
62,007
ci-security-scanning-with-strix
SkillsMP
@usestrix
添加安全扫描 CI/CD Strix — GitHub 操作, GitLab CI, 流水线 — 拉取请求获取 diff-限定范围 AI 渗透测试 blocks vulnerable 代码在…之前 merges, 结果 PR 评论 SARIF uploaded cod
Add security scanning to CI/CD with Strix — GitHub Actions, GitLab CI, or any pipeline — so every pull request gets a diff-scoped AI pentest that blocks vulnerable code before it merges, with results as PR comments and SARIF uploaded to cod
#security
usestrix/strix
Git 克隆
查看详情与安装步骤 →
安全
62,007
owasp-top-10-testing
SkillsMP
@usestrix
测试应用对照 OWASP 顶部 10 Strix — 自主 AI 智能体 attempt 真实漏洞利用分类当前 OWASP 顶部 10:2025 (broken 访问控制包括 SSRF, 安全 misconfiguration, software supply c
Test an application against the OWASP Top 10 with Strix — autonomous AI agents that attempt real exploits for each category of the current OWASP Top 10:2025 (broken access control including SSRF, security misconfiguration, software supply c
#security
usestrix/strix
Git 克隆
查看详情与安装步骤 →
安全
62,007
penetration-testing-with-strix
SkillsMP
@usestrix
渗透测试网页应用, API, 代码库, 仓库, URL, 域名, IP Strix — 自主 AI 渗透测试漏洞利用 proves 漏洞 (OWASP 顶部 10 beyond — injection, XSS, SSRF, auth/access-control flaws, IDOR, busin
Pentest a web app, API, codebase, repository, URL, domain, or IP with Strix — autonomous AI penetration testing that exploits and proves vulnerabilities (OWASP Top 10 and beyond — injection, XSS, SSRF, auth/access-control flaws, IDOR, busin
#security
usestrix/strix
Git 克隆
查看详情与安装步骤 →
安全
61,507
fortify-development
SkillsMP
@coollabsio
ACTIVATE 用户工作身份认证 Laravel. 包含 login, 注册, password reset, 邮件核验, two-factor 身份认证 (2FA/TOTP/QR codes/recovery 代码), passkeys, 个人资料更新, password confirmation
ACTIVATE when the user works on authentication in Laravel. This includes login, registration, password reset, email verification, two-factor authentication (2FA/TOTP/QR codes/recovery codes), passkeys, profile updates, password confirmation
#security
coollabsio/coolify
Git 克隆
查看详情与安装步骤 →
安全
61,507
socialite-development
SkillsMP
@coollabsio
管理 OAuth social 身份认证 Laravel Socialite. Activate 新增 social login 提供方; 配置 OAuth redirect/callback 流程; retrieving authenticated 用户细节; customizing scopes parameters; 设置项 up communit
Manages OAuth social authentication with Laravel Socialite. Activate when adding social login providers; configuring OAuth redirect/callback flows; retrieving authenticated user details; customizing scopes or parameters; setting up communit
#security
coollabsio/coolify
Git 克隆
查看详情与安装步骤 →
安全
59,903
security-and-hardening
SkillsMP
@penpot
Hardens 代码对照漏洞. 使用 handling 用户输入, 身份认证, 数据存储, 外部 integrations. 使用构建功能 accepts 不可信数据, 管理用户 sessions, 交互 third-party serv
Hardens code against vulnerabilities. Use when handling user input, authentication, data storage, or external integrations. Use when building any feature that accepts untrusted data, manages user sessions, or interacts with third-party serv
#security
penpot/penpot
Git 克隆
查看详情与安装步骤 →
安全
58,402
invalid-name
SkillsMP
@crewAIInc
技能无效名称.
This skill has an invalid name.
#security
crewaiinc/crewai
Git 克隆
查看详情与安装步骤 →
安全
56,383
setup-api-key
SkillsMP
@calesthio
指南用户设置项 up ElevenLabs API 关键 ElevenLabs MCP 工具. 使用用户需要配置 ElevenLabs API 关键, ElevenLabs 工具 fail due 缺失 API 关键, 用户提及 needing 访问 Eleve
Guides users through setting up an ElevenLabs API key for ElevenLabs MCP tools. Use when the user needs to configure an ElevenLabs API key, when ElevenLabs tools fail due to missing API key, or when the user mentions needing access to Eleve
#security
calesthio/openmontage
Git 克隆
查看详情与安装步骤 →
安全
52,934
bmad
SkillsMP
@bmad-code-org
提供规范 BMad entrypoint. 使用 root BMad 技能需要校验.
Provides the canonical BMad entrypoint. Use when the root BMad skill needs validation.
#security
bmad-code-org/bmad-method
Git 克隆
查看详情与安装步骤 →
安全
45,632
pentest-tools
SkillsMP
@sickn33
Operate 20+ penetration-testing 工具 (Nmap, Nuclei, SQLMap, FFUF, Hashcat, ) 结构化工作流程一致输出 handling.
Operate 20+ penetration-testing tools (Nmap, Nuclei, SQLMap, FFUF, Hashcat, and more) through structured workflows with consistent output handling.
#security
sickn33/agentic-awesome-skills
Git 克隆
查看详情与安装步骤 →
安全
43,963
binance
SkillsMP
@ccxt
使用 binance-命令行 Binance Spot, Futures (USD-S), 转换. 需要认证.
Use binance-cli for Binance Spot, Futures (USD-S), and Convert. Requires auth.
#security
ccxt/ccxt
Git 克隆
查看详情与安装步骤 →
安全
43,904
labarchive-integration
SkillsMP
@K-Dense-AI
Securely 集成官方 LabArchives ELN REST-例如 API 库存 API v1. 使用 regional 接口选择, signed-请求 construction, 用户授权 UID 流程, 本地 LA 容器校验, verified LabArch
Securely integrate with the official LabArchives ELN REST-like API and Inventory API v1. Use for regional endpoint selection, signed-request construction, user authorization and UID flows, local LA container validation, and verified LabArch
#security
k-dense-ai/scientific-agent-skills
Git 克隆
查看详情与安装步骤 →
安全
42,137
protected-vercel-deployments
SkillsMP
@vercel-labs
访问测试 Vercel 部署 protected Vercel 身份认证, SSO, 部署防护智能体-浏览器. 使用 preview 生产环境 URL redirects Vercel login 页面, returns 防护 401 403, 需要 short-
Access and test Vercel deployments protected by Vercel Authentication, SSO, or Deployment Protection with agent-browser. Use when a preview or production URL redirects to a Vercel login page, returns a protection 401 or 403, or needs short-
#security
vercel-labs/agent-browser
Git 克隆
查看详情与安装步骤 →
安全
40,932
feishu
SkillsMP
@Hmbown
工作 Feishu Lark bots, 文档, 工作表, bitables, approval 流程, OpenAPI/MCP 初始化设置无需 hardcoding credentials.
Work with Feishu or Lark bots, docs, sheets, bitables, approval flows, and OpenAPI/MCP setup without hardcoding credentials.
#security
hmbown/codewhale
Git 克隆
查看详情与安装步骤 →
安全
40,932
codew-release-qa-sweep
SkillsMP
@Hmbown
使用在…之前 claiming Codewhale 发布版本工作完成: 运行完整 gate 清理列表手册 QA 目标.
Use before claiming Codewhale release work is done: run the full gate sweep and list the manual QA targets.
#security
hmbown/codewhale
Git 克隆
查看详情与安装步骤 →
安全
40,932
cw-orient
SkillsMP
@Hmbown
使用启动 Codewhale 工作会话, unsure 结算, 分支, worktree authoritative: establish 线上仓库 truth 在…之前读取计划 editing 文件.
Use at the start of any Codewhale work session, or when unsure which checkout, branch, or worktree is authoritative: establish live repo truth before reading a plan or editing a file.
#security
hmbown/codewhale
Git 克隆
查看详情与安装步骤 →
安全
40,603
auth
SkillsMP
@trpc
实现 JWT/Cookie 身份认证授权 tRPC 使用 createContext 用户 extraction, t. 中间件 opts. 接下来({ ctx }) 上下文 narrowing non-null 用户, protectedProcedure 基础模式, 客户端-端授权 h
Implement JWT/cookie authentication and authorization in tRPC using createContext for user extraction, t.middleware with opts.next({ ctx }) for context narrowing to non-null user, protectedProcedure base pattern, client-side Authorization h
#security
trpc/trpc
Git 克隆
查看详情与安装步骤 →
安全
39,972
better-auth-best-practices
SkillsMP
@novuhq
技能 integrating Better 认证 - 全面 TypeScript 身份认证框架.
Skill for integrating Better Auth - the comprehensive TypeScript authentication framework.
#security
novuhq/novu
Git 克隆
查看详情与安装步骤 →
安全
39,972
nv-onboard-dcr-mcp
SkillsMP
@novuhq
入职引导新建 DCR OAuth MCP 目录入口提供方-文档 vetting curl probes. 使用新增修改 `mode: dcr` entries MCP_SERVERS. Abort 提供方需要 whitelist 手册 approval.
Onboard a new DCR OAuth MCP catalog entry with provider-doc vetting and curl probes. Use when adding or changing `mode: dcr` entries in MCP_SERVERS. Abort if the provider requires whitelist or manual approval.
#security
novuhq/novu
Git 克隆
查看详情与安装步骤 →
安全
39,613
adding-ingestion-warnings
SkillsMP
@PostHog
如何添加新建 ingestion 警告 type 事件 ingestion 流水线. 使用 emitting 新建警告 Node. js ingestion 代码 (emitIngestionWarning, captureIngestionWarning, 流水线 `warnings` 数组, `drop()` 警告), ad
How to add a new ingestion warning type to the event ingestion pipeline. Use when emitting a new warning from nodejs ingestion code (emitIngestionWarning, captureIngestionWarning, pipeline `warnings` arrays, `drop()` with warnings), when ad
#security
posthog/posthog
Git 克隆
查看详情与安装步骤 →
安全
39,613
adding-project-secret-api-key-auth
SkillsMP
@PostHog
如何 gate PostHog API 接口项目 secret API 关键 (PSAK) 认证 — 项目-限定范围, 用户-less 服务 credential. 使用新增 PSAK 支持 viewset 操作, 支持新建范围 PSAKs, handling synthetic 用户 (项目
How to gate a PostHog API endpoint with project secret API key (PSAK) auth — a project-scoped, user-less service credential. Use when adding PSAK support to a viewset action, allowing a new scope for PSAKs, handling synthetic users (Project
#security
posthog/posthog
Git 克隆
查看详情与安装步骤 →
安全
39,613
testing-mcp-tools-locally
SkillsMP
@PostHog
集合 up 本地开发环境, seed 数据, API 关键点测试 staff-only 托管迁移 MCP 工具 (托管-迁移-支持-列表, 托管-迁移-支持-获取) 端到端. 使用 testing 批量导入支持 tooling, 调试
Set up the local dev environment, seed data, and API keys to test the staff-only managed migrations MCP tools (managed-migrations-support-list, managed-migrations-support-get) end to end. Use when testing batch import support tooling, debug
#security
posthog/posthog
Git 克隆
查看详情与安装步骤 →
安全
39,485
wcag-audit-patterns
SkillsMP
@wshobson
Conduct WCAG 2.2 无障碍审计自动化 testing, 手册核验, remediation 指引. 使用审计网站无障碍, 修复 WCAG violations, 实现 accessible 设计模式.
Conduct WCAG 2.2 accessibility audits with automated testing, manual verification, and remediation guidance. Use when auditing websites for accessibility, fixing WCAG violations, or implementing accessible design patterns.
#security
wshobson/agents
Git 克隆
查看详情与安装步骤 →
安全
39,485
secrets-management
SkillsMP
@wshobson
实现安全 secrets 管理 CI/CD 流水线使用 Vault, AWS Secrets Manager, 原生平台解决方案. 使用 handling sensitive credentials, rotating secrets, 防护 CI/CD environments.
Implement secure secrets management for CI/CD pipelines using Vault, AWS Secrets Manager, or native platform solutions. Use when handling sensitive credentials, rotating secrets, or securing CI/CD environments.
#security
wshobson/agents
Git 克隆
查看详情与安装步骤 →
安全
39,485
mtls-configuration
SkillsMP
@wshobson
配置 mutual TLS (mTLS) zero-trust 服务-to-服务 communication. 使用实现 zero-trust 联网, 证书管理, 防护内部服务 communication.
Configure mutual TLS (mTLS) for zero-trust service-to-service communication. Use when implementing zero-trust networking, certificate management, or securing internal service communication.
#security
wshobson/agents
Git 克隆
查看详情与安装步骤 →
安全
39,485
auth-implementation-patterns
SkillsMP
@wshobson
主分支身份认证授权模式包括 JWT, OAuth2, 会话管理, RBAC 构建安全, 可扩展访问控制系统. 使用实现认证系统, 防护 APIs, 调试安全工单.
Master authentication and authorization patterns including JWT, OAuth2, session management, and RBAC to build secure, scalable access control systems. Use when implementing auth systems, securing APIs, or debugging security issues.
#security
wshobson/agents
Git 克隆
查看详情与安装步骤 →
安全
39,485
sast-configuration
SkillsMP
@wshobson
配置静态应用安全 Testing (SAST) 工具自动化漏洞检测应用代码. 使用设置项 up 安全扫描, 实现 DevSecOps practices, automating 代码漏洞检测.
Configure Static Application Security Testing (SAST) tools for automated vulnerability detection in application code. Use when setting up security scanning, implementing DevSecOps practices, or automating code vulnerability detection.
#security
wshobson/agents
Git 克隆
查看详情与安装步骤 →
安全
38,947
mobile-e2e
SkillsMP
@RSSNext
运行 apps/mobile Maestro 端到端测试仓库. 使用智能体需要校验移动端认证流程 iOS Simulator 安卓 Emulator. 当前维护 coverage register, sign 输出, sign.
Run apps/mobile Maestro end-to-end tests in this repo. Use when an agent needs to validate mobile auth flows on iOS Simulator or Android Emulator. Current maintained coverage is register, sign out, and sign in.
#security
rssnext/folo
Git 克隆
查看详情与安装步骤 →
安全
38,754
agent-owasp-compliance
SkillsMP
@github
检查 AI 智能体代码库对照 OWASP Agentic 安全 Initiative (ASI) 顶部 10 风险. 使用技能: - Evaluating 智能体系统's 安全 posture 在…之前生产环境部署 - Running 合规检查对照 OWASP ASI 2
Check any AI agent codebase against the OWASP Agentic Security Initiative (ASI) Top 10 risks. Use this skill when: - Evaluating an agent system's security posture before production deployment - Running a compliance check against OWASP ASI 2
#security
github/awesome-copilot
Git 克隆
查看详情与安装步骤 →
安全
38,754
agent-supply-chain
SkillsMP
@github
核验供应链 integrity AI 智能体插件, 工具, 依赖. 使用技能: - 生成 SHA-256 integrity manifests 智能体插件 tool 软件包 - Verifying 已安装插件匹配发布 manifests
Verify supply chain integrity for AI agent plugins, tools, and dependencies. Use this skill when: - Generating SHA-256 integrity manifests for agent plugins or tool packages - Verifying that installed plugins match their published manifests
#security
github/awesome-copilot
Git 克隆
查看详情与安装步骤 →
安全
38,754
arize-ai-provider-integration
SkillsMP
@github
创建, 读取, 更新, deletes Arize AI integrations 存储 LLM 提供方 credentials 用于 evaluators 其他 Arize 功能. 支持 LLM 提供方 (e. g. OpenAI, Anthropic, Azure OpenAI, AWS Bedrock, Vertex AI, Gemini, NVI
Creates, reads, updates, and deletes Arize AI integrations that store LLM provider credentials used by evaluators and other Arize features. Supports any LLM provider (e.g. OpenAI, Anthropic, Azure OpenAI, AWS Bedrock, Vertex AI, Gemini, NVI
#security
github/awesome-copilot
Git 克隆
查看详情与安装步骤 →
安全
38,754
azure-role-selector
SkillsMP
@github
用户 asking 指引角色 assign identity 给定 desired 权限, 智能体帮助 understand 角色 meet 需求 least privilege 访问如何应用角色.
When user is asking for guidance for which role to assign to an identity given desired permissions, this agent helps them understand the role that will meet the requirements with least privilege access and how to apply that role.
#security
github/awesome-copilot
Git 克隆
查看详情与安装步骤 →
安全
38,754
salesforce-component-standards
SkillsMP
@github
质量标准 Salesforce Lightning 网页组件 (LWC), Aura 组件, Visualforce 页面. 覆盖 SLDS 2 合规, 无障碍 (WCAG 2.1 AA), 数据访问模式选择, 组件 communication 规则, XSS prevention, CS
Quality standards for Salesforce Lightning Web Components (LWC), Aura components, and Visualforce pages. Covers SLDS 2 compliance, accessibility (WCAG 2.1 AA), data access pattern selection, component communication rules, XSS prevention, CS
#security
github/awesome-copilot
Git 克隆
查看详情与安装步骤 →
安全
35,034
competition-ad-certificate-abuse
SkillsMP
@zhaoxuya520
内部下游技能 ctf-沙箱-orchestrator. CTF-沙箱工作流程 AD CS, 证书模板, enrollment rights, EKUs, SAN 控件, PKINIT, 证书映射, 证书-基于 privilege 路径. 使用用户要求
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for AD CS, certificate templates, enrollment rights, EKUs, SAN controls, PKINIT, certificate mapping, and cert-based privilege paths. Use when the user asks about
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
competition-android-hooking
SkillsMP
@zhaoxuya520
内部下游技能 ctf-沙箱-orchestrator. CTF-沙箱工作流程安卓 APK hooking, Frida 链路追踪, 请求-signing recovery, SSL pinning bypass, JNI 边界 inspection, 应用 trust-边界分析. 使用用户
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for Android APK hooking, Frida tracing, request-signing recovery, SSL pinning bypass, JNI boundary inspection, and app trust-boundary analysis. Use when the user a
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
competition-cloud-metadata-path
SkillsMP
@zhaoxuya520
内部下游技能 ctf-沙箱-orchestrator. CTF-沙箱工作流程云端元数据服务, instance identity, workload identity, 链接-本地 credential 路径, 角色 assumption, 元数据-to-privilege trust edges. 使用 th
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for cloud metadata services, instance identity, workload identity, link-local credential paths, role assumption, and metadata-to-privilege trust edges. Use when th
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
competition-crypto-mobile
SkillsMP
@zhaoxuya520
内部下游技能 ctf-沙箱-orchestrator. CTF-沙箱工作流程加密货币, encoding, steganography, APK, IPA, 移动端 trust-边界 challenges. 使用用户要求 decode blob, recover 转换 chain 关键, ins
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for crypto, encoding, steganography, APK, IPA, and mobile trust-boundary challenges. Use when the user asks to decode a blob, recover a transform chain or key, ins
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
competition-jwt-claim-confusion
SkillsMP
@zhaoxuya520
内部下游技能 ctf-沙箱-orchestrator. CTF-沙箱工作流程 JWT, JWS, JWE 校验路径, 页眉解析, 关键选择, claim acceptance, 受众 issuer 检查, 角色 derivation, 词元-to-identity confusi
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for JWT, JWS, and JWE validation paths, header parsing, key selection, claim acceptance, audience and issuer checks, role derivation, and token-to-identity confusi
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
competition-lsass-ticket-material
SkillsMP
@zhaoxuya520
内部下游技能 ctf-沙箱-orchestrator. CTF-沙箱工作流程 LSASS-resident secrets, Windows logon sessions, Kerberos ticket 缓存, DPAPI-backed material, SSP 产物, replayable credential extraction. 使用 th
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for LSASS-resident secrets, Windows logon sessions, Kerberos ticket caches, DPAPI-backed material, SSP artifacts, and replayable credential extraction. Use when th
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
competition-mailbox-abuse
SkillsMP
@zhaoxuya520
内部下游技能 ctf-沙箱-orchestrator. CTF-沙箱工作流程 enterprise mail abuse, OAuth consent, inbox forwarding 规则, transport 规则, 共享 mailbox 访问, 钓鱼攻击 chains, 词元-to-mailbox 端 effects. Us
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for enterprise mail abuse, OAuth consent, inbox or forwarding rules, transport rules, shared mailbox access, phishing chains, and token-to-mailbox side effects. Us
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
competition-oauth-oidc-chain
SkillsMP
@zhaoxuya520
内部下游技能 ctf-沙箱-orchestrator. CTF-沙箱工作流程 OAuth, OIDC, redirect 流程, 状态 nonce handling, PKCE, 词元 exchange, refresh 逻辑, claim 映射, accepted login 路径. 使用用户要求 t
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for OAuth, OIDC, redirect flows, state or nonce handling, PKCE, token exchange, refresh logic, claim mapping, and accepted login paths. Use when the user asks to t
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
competition-relay-coercion-chain
SkillsMP
@zhaoxuya520
内部下游技能 ctf-沙箱-orchestrator. CTF-沙箱工作流程 forced-认证 coercion, relay chains, 目标选择, NTLM 相关 acceptance 路径, coercion-to-privilege 过渡动画. 使用用户要求链路追踪
Internal downstream skill for ctf-sandbox-orchestrator. CTF-sandbox workflow for forced-auth coercion, relay chains, target selection, NTLM or related acceptance paths, and coercion-to-privilege transitions. Use when the user asks to trace
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
ctf-sandbox-orchestrator
SkillsMP
@zhaoxuya520
默认 entrypoint 主分支 ctf-沙箱-orchestrator 工作流程 CTF, 漏洞利用, reverse 工程, DFIR, pwnable, 加密货币, stego, 移动端, AI-智能体, 云端, 容器, 活动目录, Windows-主机, identity challenges. 使用首先
Default entrypoint and master ctf-sandbox-orchestrator workflow for CTF, exploit, reverse engineering, DFIR, pwnable, crypto, stego, mobile, AI-agent, cloud, container, Active Directory, Windows-host, and identity challenges. Use first when
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
api-security
SkillsMP
@zhaoxuya520
使用经授权安全 assessment REST, GraphQL, WebSocket, SOAP APIs, 包括 discovery, 身份认证, 授权, rate-限量, CI/CD testing.
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including discovery, authentication, authorization, rate-limit, and CI/CD testing.
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
cloud-k8s
SkillsMP
@zhaoxuya520
使用经授权云端, 容器, Kubernetes 安全 assessment 包括元数据 SSRF, IAM misconfig, 容器 escape 路径, 集群 RBAC 评审.
Use for authorized cloud, container, and Kubernetes security assessment including metadata SSRF, IAM misconfig, container escape paths, and cluster RBAC review.
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
code-audit
SkillsMP
@zhaoxuya520
使用经授权来源-代码安全评审 SAST 工作流程包括 Semgrep, CodeQL 模式, dangerous API hunting, 修复核验.
Use for authorized source-code security review and SAST workflows including Semgrep, CodeQL patterns, dangerous API hunting, and fix verification.
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
database-security
SkillsMP
@zhaoxuya520
使用经授权数据库安全 assessment 覆盖 PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/命令路径, misconfiguration 评审.
Use for authorized database security assessment covering PostgreSQL/MySQL/MSSQL/Mongo/Redis exposure, authz, UDF/command paths, and misconfiguration review.
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
email-security
SkillsMP
@zhaoxuya520
使用经授权邮件安全评审包括钓鱼攻击分析, 页眉身份认证 (SPF/DKIM/DMARC), BEC 模式, mailbox 词元 abuse 研究.
Use for authorized email security review including phishing analysis, header authentication (SPF/DKIM/DMARC), BEC patterns, and mailbox token abuse research.
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
firmware-pentest
SkillsMP
@zhaoxuya520
固件 / IoT 渗透链。从拿到一坨. bin /. img 开始,闭环走完逆向 → 提取 → 模拟 → 利用。 方法论遵循 OWASP FSTM 九阶段;工具链以 binwalk v3、unblob、EMBA、Firmadyne、AFL++ 为主。 适用场景:路由器/摄像头/智能家居固件审计、固件升级包逆向、IoT CVE 复现、嵌入式 0day 挖掘。 触发关键词:固件、固件、IoT、binwalk、unblob、UART、JTAG、squashfs、UBI、
固件 / IoT 渗透链。从拿到一坨 .bin / .img 开始,闭环走完逆向 → 提取 → 模拟 → 利用。 方法论遵循 OWASP FSTM 九阶段;工具链以 binwalk v3、unblob、EMBA、Firmadyne、AFL++ 为主。 适用场景:路由器/摄像头/智能家居固件审计、固件升级包逆向、IoT CVE 复现、嵌入式 0day 挖掘。 触发关键词:固件、firmware、IoT、binwalk、unblob、UART、JTAG、squashfs、UBI、
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
identity-federation
SkillsMP
@zhaoxuya520
使用经授权 assessment federated identity 系统包括 SAML, OIDC, OAuth2 流程, SSO misconfiguration, 词元 confusion 工单.
Use for authorized assessment of federated identity systems including SAML, OIDC, OAuth2 flows, SSO misconfiguration, and token confusion issues.
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
mobile-reverse
SkillsMP
@zhaoxuya520
使用经授权安卓 iOS 应用 reverse 工程安全 testing, 包括 APK IPA 分析, 运行时 instrumentation, SSL pinning, 平台防护检查.
Use for authorized Android or iOS application reverse engineering and security testing, including APK or IPA analysis, runtime instrumentation, SSL pinning, and platform protection checks.
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
pentest-tools
SkillsMP
@zhaoxuya520
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、网页渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP 服务端(pentestMCP / MCP-安全-中心)将 20+ 安全工具暴露给 AI 智能体。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、网页渗透、ZAP、Burp。
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
reverse-engineering
SkillsMP
@zhaoxuya520
提供 reverse 工程 techniques. 使用 main 作业 understand 编译, obfuscated, packed, virtualized 目标工作在…之前 exploiting solving, 包括 binaries, APKs, WASM, 固件, 自定义 VMs, bytecode,
Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode,
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
thick-client
SkillsMP
@zhaoxuya520
使用经授权安全 testing 桌面 thick 客户端包括本地存储, 更新通道, IPC, traffic, 客户端-端 trust 边界.
Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries.
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
threat-intelligence
SkillsMP
@zhaoxuya520
使用经授权 OSINT cyber threat intelligence enriches IOCs, 营销活动, impersonation, 诈骗, threat actors 公开 sources. 包含 bounded X/Twitter 搜索 Xquik, 来源 preservation, corroboration, evide
Use for authorized OSINT and cyber threat intelligence that enriches IOCs, campaigns, impersonation, scams, or threat actors from public sources. Includes bounded X/Twitter search through Xquik, source preservation, corroboration, and evide
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
35,034
wifi-wireless
SkillsMP
@zhaoxuya520
使用经授权 wireless 安全 assessment 包括 Wi-Fi 采集, WPA handshake 分析, rogue AP 检测研究, lab-only deauth testing.
Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing.
#security
zhaoxuya520/reverse-skill
Git 克隆
查看详情与安装步骤 →
安全
33,086
wxjava-troubleshooter
SkillsMP
@binarywang
排查 WxJava 在配置初始化、访问词元、签名验签、支付证书、回调通知、序列化、网络请求和多账号隔离方面的问题。适用于用户提供异常、日志、请求响应或“WxJava 为什么不能调用”的场景。
排查 WxJava 在配置初始化、access token、签名验签、支付证书、回调通知、序列化、网络请求和多账号隔离方面的问题。适用于用户提供异常、日志、请求响应或“WxJava 为什么不能调用”的场景。
#security
binarywang/wxjava
Git 克隆
查看详情与安装步骤 →
安全
33,086
wxjava-upgrade-guide
SkillsMP
@binarywang
规划 WxJava 的版本升级与迁移,检查 BOM、模块依赖、Java 版本、配置与公共 API 兼容性,并提供可回滚的验证步骤。适用于用户从旧版升级、切换依赖管理方式、处理兼容性告警或制定升级发布计划时。
#security
binarywang/wxjava
Git 克隆
查看详情与安装步骤 →
安全
33,024
data-routing
SkillsMP
@HKUDS
单个 ROUTER 数据 need. 加载技能 BEFORE backtest, 数据-获取, 研究任务 pick best 可用 source/tool, honour 认证 (env) 需求, 避免 ban-风险提供方.
The single ROUTER for every data need. Load this skill BEFORE any backtest, data-fetch, or research task to pick the best available source/tool, honour auth (env) requirements, and avoid ban-risk providers.
#security
hkuds/vibe-trading
Git 克隆
查看详情与安装步骤 →
安全
32,390
abusing-dpapi-for-credential-access
SkillsMP
@mukul975
提取解密 Windows DPAPI-protected secrets (Credential Manager, 浏览器 logins/cookies, Wi-Fi credentials, KeePass 关键点) 在线离线使用 SharpDPAPI, SharpChrome, Mimikatz, Impacket's dpapi. py, 包括域名-wide decry
Extract and decrypt Windows DPAPI-protected secrets (Credential Manager, browser logins/cookies, Wi-Fi credentials, KeePass keys) online or offline using SharpDPAPI, SharpChrome, Mimikatz, or Impacket's dpapi.py, including domain-wide decry
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
analyzing-active-directory-acl-abuse
SkillsMP
@mukul975
检测 dangerous ACL misconfigurations 活动目录使用 ldap3 识别 GenericAll, WriteDACL, WriteOwner abuse 路径
Detect dangerous ACL misconfigurations in Active Directory using ldap3 to identify GenericAll, WriteDACL, and WriteOwner abuse paths
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
analyzing-ios-app-security-with-objection
SkillsMP
@mukul975
运行时 iOS 应用安全 testing Objection (Frida): 检查 keychain filesystem 数据, 探索应用 internals 运行时, validate/bypass 客户端-端 protections 在…期间经授权移动端 assessments.
Runtime iOS app security testing with Objection (Frida): inspect keychain and filesystem data, explore app internals at runtime, and validate/bypass client-side protections during authorized mobile assessments.
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
attacking-entra-id-with-roadtools
SkillsMP
@mukul975
Enumerate Microsoft Entra ID (Azure AD) tenants ROADrecon acquire, exchange, abuse 词元 (包括 primary refresh 词元) roadtx. 使用经授权 red-团队 enumeration tenant's 目录对象词元-基础
Enumerate Microsoft Entra ID (Azure AD) tenants with ROADrecon and acquire, exchange, and abuse tokens (including primary refresh tokens) with roadtx. Use for authorized red-team enumeration of a tenant's directory objects or for token-base
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
attacking-oauth-with-device-code-phishing
SkillsMP
@mukul975
运行 OAuth 2.0 设备-代码 illicit-consent 钓鱼攻击 attacks 对照 Microsoft Entra ID, 使用 TokenTactics-风格 tooling steal 访问 refresh 词元, bypass MFA, pivot 跨 Microsoft 365 服务. 使用经授权 red-团队
Run OAuth 2.0 device-code and illicit-consent phishing attacks against Microsoft Entra ID, using TokenTactics-style tooling to steal access and refresh tokens, bypass MFA, and pivot across Microsoft 365 services. Use for authorized red-team
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
auditing-aws-s3-bucket-permissions
SkillsMP
@mukul975
Systematically 审计 AWS S3 bucket 权限识别 publicly accessible buckets, overly permissive ACLs, misconfigured bucket 政策, 缺失加密设置使用 AWS CLI, S3audit, Prowler enforce least-privilege da
Systematically audit AWS S3 bucket permissions to identify publicly accessible buckets, overly permissive ACLs, misconfigured bucket policies, and missing encryption settings using AWS CLI, S3audit, and Prowler to enforce least-privilege da
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
auditing-azure-active-directory-configuration
SkillsMP
@mukul975
审计 Microsoft Entra ID (Azure 活动目录) 配置识别 risky 身份认证政策, overly permissive 角色 assignments, stale 账号, conditional 访问 gaps, guest 用户风险使用 AzureAD PowerShell, Micros
Auditing Microsoft Entra ID (Azure Active Directory) configuration to identify risky authentication policies, overly permissive role assignments, stale accounts, conditional access gaps, and guest user risks using AzureAD PowerShell, Micros
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
auditing-cloud-with-cis-benchmarks
SkillsMP
@mukul975
审计 AWS, Azure, GCP environments 对照 CIS Foundations 基准测试 running 自动化扫描工具例如 Prowler ScoutSuite, interpreting 失败控件, 跟踪 remediation continuous 合规. 使用 cond
Audit AWS, Azure, and GCP environments against the CIS Foundations Benchmarks by running automated scans with tools like Prowler and ScoutSuite, interpreting failed controls, and tracking remediation for continuous compliance. Use when cond
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
auditing-entra-id-with-aadinternals
SkillsMP
@mukul975
云端硬盘 AADInternals PowerShell 工具集 perform Microsoft Entra ID tenant 侦察, 访问-词元 acquisition 跨 Microsoft APIs, federation/AD FS backdoor testing (Golden SAML, T1606.002) defensive 校验. 使用 duri
Drive the AADInternals PowerShell toolkit to perform Microsoft Entra ID tenant reconnaissance, access-token acquisition across Microsoft APIs, and federation/AD FS backdoor testing (Golden SAML, T1606.002) for defensive validation. Use duri
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
auditing-kubernetes-rbac-privilege-escalation
SkillsMP
@mukul975
查找 over-permissive RBAC 角色服务-账号词元 abuse 路径 Kubernetes 集群使用 kubectl 认证 can-i, rbac-police, kubectl-who-can, rakkess, 链路追踪 subjects escalate toward 集群-管理员. 使用评审
Finds over-permissive RBAC roles and service-account token abuse paths in a Kubernetes cluster using kubectl auth can-i, rbac-police, kubectl-who-can, and rakkess, tracing which subjects can escalate toward cluster-admin. Use when reviewing
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
building-automated-malware-submission-pipeline
SkillsMP
@mukul975
构建自动化恶意软件 submission 分析流水线 collects suspicious 文件接口邮件 gateways, submits 沙箱 environments 多-引擎 scanners, 生成 verdicts IOCs SIEM integra
Builds an automated malware submission and analysis pipeline that collects suspicious files from endpoints and email gateways, submits them to sandbox environments and multi-engine scanners, and generates verdicts with IOCs for SIEM integra
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
building-identity-federation-with-saml-azure-ad
SkillsMP
@mukul975
配置 SAML 2.0 identity federation on-premises 活动目录 (通过 AD FS third-party IdP) Microsoft Entra ID, 覆盖 federation 模型 (AD FS, password 哈希同步, pass-through 认证, third-party IdP) SAML aut
Configure SAML 2.0 identity federation between on-premises Active Directory (via AD FS or a third-party IdP) and Microsoft Entra ID, covering federation models (AD FS, password hash sync, pass-through auth, third-party IdP) and the SAML aut
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
building-phishing-reporting-button-workflow
SkillsMP
@mukul975
实现钓鱼攻击报告按钮 (Microsoft 365 构建- 报告按钮 third-party 例如 KnowBe4/Cofense) 邮件客户端 SOAR-driven 自动化分诊工作流程 classifies reported 邮件, 提取 IOCs, takes remediation ac
Implement a phishing report button (Microsoft 365 built-in Report button or third-party like KnowBe4/Cofense) in email clients with a SOAR-driven automated triage workflow that classifies reported emails, extracts IOCs, takes remediation ac
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
building-role-mining-for-rbac-optimization
SkillsMP
@mukul975
应用底部-up 顶部-down 角色 mining techniques, 包括聚类算法 formal concept 分析, 发现 optimal RBAC 角色现有用户-权限 assignments, consolidating overlapping 角色 enforcing least
Apply bottom-up and top-down role mining techniques, including clustering algorithms and formal concept analysis, to discover optimal RBAC roles from existing user-permission assignments, consolidating overlapping roles and enforcing least
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
building-soc-playbook-for-ransomware
SkillsMP
@mukul975
构建结构化 SOC incident 响应操作手册 ransomware attacks 覆盖检测, containment, eradication, recovery 阶段特定 SIEM 查询, 隔离 procedures, 决策 trees. 使用 SOC teams need formal
Builds a structured SOC incident response playbook for ransomware attacks covering detection, containment, eradication, and recovery phases with specific SIEM queries, isolation procedures, and decision trees. Use when SOC teams need formal
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
building-threat-feed-aggregation-with-misp
SkillsMP
@mukul975
部署 MISP 通过 Docker 配置 feeds sources 例如 abuse. ch, AlienVault OTX, CIRCL 聚合, correlate, distribute threat intelligence, 包括自动化 feed synchronization STIX/TAXII-基于集成 Spl
Deploy MISP via Docker and configure feeds from sources like abuse.ch, AlienVault OTX, and CIRCL to aggregate, correlate, and distribute threat intelligence, including automated feed synchronization and STIX/TAXII-based integration with Spl
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
building-threat-intelligence-enrichment-in-splunk
SkillsMP
@mukul975
构建自动化 IOC enrichment 流水线 Splunk Enterprise 安全 ingesting threat feeds KV 存储合集 correlating 对照安全事件通过查找表格, 模块化输入, Threat Intelligence 框架
Build automated IOC enrichment pipelines in Splunk Enterprise Security by ingesting threat feeds into KV Store collections and correlating them against security events via lookup tables, modular inputs, and the Threat Intelligence Framework
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
building-threat-intelligence-feed-integration
SkillsMP
@mukul975
构建自动化 threat intelligence feed 集成流水线 connecting STIX/TAXII feeds, 开源 threat intel, commercial TI 平台 SIEM 安全工具实时 IOC 匹配 alerting. 使用 SOC teams need
Builds automated threat intelligence feed integration pipelines connecting STIX/TAXII feeds, open-source threat intel, and commercial TI platforms into SIEM and security tools for real-time IOC matching and alerting. Use when SOC teams need
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
building-vulnerability-exception-tracking-system
SkillsMP
@mukul975
构建漏洞异常风险 acceptance 跟踪系统覆盖 approval 工作流程, compensating 控件文档, 自动 expiration 漏洞 miss SLA remediation timelines. 使用 standing up g
Build a vulnerability exception and risk acceptance tracking system covering approval workflows, compensating controls documentation, and automatic expiration for vulnerabilities that miss SLA remediation timelines. Use when standing up a g
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
building-vulnerability-scanning-workflow
SkillsMP
@mukul975
构建结构化漏洞扫描工作流程使用工具例如 Nessus, Qualys, OpenVAS 发现, prioritize, 跟踪 remediation 安全漏洞跨 基础设施. 使用 SOC teams need establish recurrin
Builds a structured vulnerability scanning workflow using tools like Nessus, Qualys, and OpenVAS to discover, prioritize, and track remediation of security vulnerabilities across infrastructure. Use when SOC teams need to establish recurrin
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
bypassing-authentication-with-forced-browsing
SkillsMP
@mukul975
Discovering accessing unprotected 页面, APIs, administrative 接口定义 enumerating URLs bypassing 身份认证控件在…期间经授权安全 assessments.
Discovering and accessing unprotected pages, APIs, and administrative interfaces by enumerating URLs and bypassing authentication controls during authorized security assessments.
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
coercing-authentication-with-coercer-petitpotam
SkillsMP
@mukul975
触发 machine 账号身份认证 PetitPotam (MS-EFSR) Coercer (MS-RPRN, MS-DFSNM, MS-FSRVP, MS-EVEN) 通过 Coercer's scan/coerce/fuzz modes, feeding coerced NTLM 认证 relay 对照 AD CS 网页 Enrollment (ESC8), LDAP (
Trigger machine account authentication with PetitPotam (MS-EFSR) and Coercer (MS-RPRN, MS-DFSNM, MS-FSRVP, MS-EVEN) via Coercer's scan/coerce/fuzz modes, feeding the coerced NTLM auth into a relay against AD CS Web Enrollment (ESC8), LDAP (
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
conducting-api-security-testing
SkillsMP
@mukul975
Conducts 安全 testing REST, GraphQL, gRPC APIs 识别漏洞身份认证, 授权, 频率限制, 输入校验, 业务逻辑. tester 使用 OWASP API 安全顶部 10 testing framew
Conducts security testing of REST, GraphQL, and gRPC APIs to identify vulnerabilities in authentication, authorization, rate limiting, input validation, and business logic. The tester uses the OWASP API Security Top 10 as the testing framew
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
conducting-cloud-penetration-testing
SkillsMP
@mukul975
技能 outlines methodologies performing 经授权渗透测试对照 AWS, Azure, GCP 云端 environments. 覆盖 understanding 共享 responsibility 模型 testing 范围, leveraging 云端-特定 attack tool
This skill outlines methodologies for performing authorized penetration testing against AWS, Azure, and GCP cloud environments. It covers understanding the shared responsibility model for testing scope, leveraging cloud-specific attack tool
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
conducting-cyber-risk-assessment-with-nist-800-30
SkillsMP
@mukul975
Conduct defensible cybersecurity 风险 assessment 使用 NIST SP 800-30 Rev 1 methodology: 准备范围风险模型, 识别 threat sources threat 事件, 识别漏洞 predisposing conditions, determine likeli
Conduct a defensible cybersecurity risk assessment using the NIST SP 800-30 Rev 1 methodology: prepare scope and a risk model, identify threat sources and threat events, identify vulnerabilities and predisposing conditions, determine likeli
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
conducting-internal-network-penetration-test
SkillsMP
@mukul975
执行内部网络渗透测试 simulating insider threat 帖子-breach attacker 识别 lateral movement 路径, privilege escalation vectors, sensitive 数据 exposure 在…内 corporate 网络.
Execute an internal network penetration test simulating an insider threat or post-breach attacker to identify lateral movement paths, privilege escalation vectors, and sensitive data exposure within the corporate network.
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
conducting-man-in-the-middle-attack-simulation
SkillsMP
@mukul975
Simulates man-in-the-中间 attacks 使用 Ettercap, mitmproxy, Bettercap 经授权 environments intercept, 分析, 修改网络 traffic testing 加密 enforcement, 证书校验, 检测能力
Simulates man-in-the-middle attacks using Ettercap, mitmproxy, and Bettercap in authorized environments to intercept, analyze, and modify network traffic for testing encryption enforcement, certificate validation, and detection capabilities
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
conducting-mobile-app-penetration-test
SkillsMP
@mukul975
Conducts 渗透测试 iOS 安卓移动端应用以下 OWASP 移动端应用安全 Testing 指南 (MASTG) 识别漏洞数据存储, 网络 communication, 身份认证, cryptography,
Conducts penetration testing of iOS and Android mobile applications following the OWASP Mobile Application Security Testing Guide (MASTG) to identify vulnerabilities in data storage, network communication, authentication, cryptography, and
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
conducting-network-penetration-test
SkillsMP
@mukul975
Conducts 全面网络 penetration 测试对照经授权目标 environments performing 主机 discovery, port 扫描, 服务 enumeration, 漏洞 identification, controlled exploitation assess 安全 postu
Conducts comprehensive network penetration tests against authorized target environments by performing host discovery, port scanning, service enumeration, vulnerability identification, and controlled exploitation to assess the security postu
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
安全
32,390
conducting-pass-the-ticket-attack
SkillsMP
@mukul975
Perform Pass-the-Ticket (PtT) lateral movement extracting Kerberos TGT/TGS tickets LSASS 记忆 compromised 主机 injecting another 会话 impersonate ticket 所有者无需 knowing password. 使用在…期间
Perform Pass-the-Ticket (PtT) lateral movement by extracting Kerberos TGT/TGS tickets from LSASS memory on a compromised host and injecting them into another session to impersonate the ticket owner without knowing their password. Use during
#security
mukul975/anthropic-cybersecurity-skills
Git 克隆
查看详情与安装步骤 →
精选推荐
社区热度
安装通道
运行环境
命令行 AI Agent
功能描述与核心用途
运行宿主与模型建议
安装与使用教程
发给 AI 的安装提示词
复制提示词
调用示例(自然语言)
关联标签
查看 GitHub 开源源码
本页永久链接 ↗
提交 Skill 同步收录
GitHub 地址识别
上传文件识别
Skill 开源地址(GitHub 仓库 URL / owner/repo)
解析并安全校验
上传 Skill 文件(SKILL.md / README / LICENSE / package.json,可多选或选整个文件夹)
点击选择文件,或把 Skill 文件夹直接拖进来
至少包含 SKILL.md 或 README;文本文件即可,不会上传二进制内容
选择文件
选择整个文件夹
识别并自动分区
开源安全校验
…
仓库公开可访问
待校验
…
包含 SKILL.md / README(Skill 本体)
待校验
…
安全扫描:无高危安装脚本 / 混淆命令
待校验
我已人工审查该仓库源码与安装脚本,确认安全
收录到哪个区域
自定义区域名称(2–10 字)
区域高光颜色
名称
作者
简介
标签(逗号分隔,可修改)
提交收录与同步教程
取消
确认收录到区域
我提交收录的 Skill
导出收录记录(JSON)
导入记录
已复制到剪贴板