Skip to main content
zhaoxuya520
ملف منشئ GitHub

zhaoxuya520

عرض على مستوى المستودعات لـ ٢١٩ skills مجمعة عبر ٢ مستودعات GitHub.

skills مجمعة
٢١٩
مستودعات
٢
محدث
٢٦ أغسطس ٢٠٢٦
مستكشف المستودعات

المستودعات و skills الممثلة

auth-permission
محللو أمن المعلومات

设计 API 认证鉴权和权限矩阵时使用。适用于多角色系统、租户隔离、字段级权限。优先使用 OAuth 2.0 / JWT + RBAC + 资源归属检查。

١٩ مايو ٢٠٢٦
endpoint-design
مطوّرو البرمجيات

设计具体 API 端点时使用。适用于资源建模后的下一步、列端点清单、HTTP 方法和状态码选择。优先使用 RFC 7231 HTTP 语义 + GitHub REST 命名规范。

١٩ مايو ٢٠٢٦
error-handling
مطوّرو البرمجيات

设计 API 错误码和错误结构时使用。适用于错误响应规范、调用方错误处理、调试可观测。优先使用 RFC 7807 Problem Details + 业务错误码 + 调用方处理建议。

١٩ مايو ٢٠٢٦
idempotency-retry
مطوّرو البرمجيات

设计幂等接口和重试策略时使用。适用于支付、扣减、订单、关键写操作。优先使用 Idempotency-Key + 业务去重键 + 并发冲突处理(ETag/版本号)。

١٩ مايو ٢٠٢٦
openapi-mock
مطوّرو البرمجيات

输出 OpenAPI 契约和 Mock 服务时使用。适用于 API 设计的最后一步、给前端/后端/QA 的交付。优先使用 OpenAPI 3.1 + Mock 数据覆盖所有路径 + 详细的下游交接清单。

١٩ مايو ٢٠٢٦
pagination-filtering
مطوّرو البرمجيات

设计列表接口的分页、筛选、排序、搜索时使用。适用于所有列表 API。优先使用 cursor 分页(大数据)或 offset 分页(小数据)+ 统一筛选/排序规范。

١٩ مايو ٢٠٢٦
request-response
مطوّرو البرمجيات

设计请求和响应结构时使用。适用于字段定义、校验规则、响应格式。优先使用 JSON:API 风格 + 字段稳定性 + 完整校验规则。

١٩ مايو ٢٠٢٦
resource-modeling
مطوّرو البرمجيات

把业务对象建模为 REST 资源时使用。适用于 API 设计起点、复杂业务对象抽象、资源关系定义。优先使用 REST 资源模型 + 集合/单资源/子资源/动作四种模式。

١٩ مايو ٢٠٢٦
عرض 8 من أصل ١٣٢ skills مجمعة.
reverse-engineering
غير مصنف

Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, malware-like…

٢٦ أغسطس ٢٠٢٦
reverse-skill-router
غير مصنف

Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is…

٢٦ أغسطس ٢٠٢٦
case-review
محللو أمن المعلومات

Reviews a reverse-skill case package for scope readiness, Evidence to Finding to Path traceability, work item coverage, timeline references, and optional artifact hash integrity before report handoff.

٢٤ أغسطس ٢٠٢٦
threat-intelligence
غير مصنف

Use for authorized OSINT and cyber threat intelligence that enriches IOCs, campaigns, impersonation, scams, or threat actors from public sources. Includes bounded X/Twitter search through Xquik, source preservation, corroboration, and evidence handoff.

٢٢ أغسطس ٢٠٢٦
js-reverse
غير مصنف

在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse_* 工具,需要更强的浏览器/CDP/Hook 面时联动 jshookmcp。

١٩ أغسطس ٢٠٢٦
pentest-tools
غير مصنف

主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。

١٩ أغسطس ٢٠٢٦
ida-reverse
غير مصنف

IDA Pro 逆向分析辅助技能。当用户提到逆向、反编译、分析二进制/PE/ELF/APK/DLL/SO、破解、找密码、漏洞分析、病毒分析、firmware 固件分析,或需要分析 exe/dll/so/elf/macho/sys 等文件时,务必使用此技能。 Ensure to use this skill when the user wants to analyze any binary file, regardless of whether they explicitly mention "IDA" or…

١٩ أغسطس ٢٠٢٦
attack-chain
غير مصنف

Use for authorized multi-stage attack-path planning and orchestration when a task spans reconnaissance, initial access, privilege escalation, lateral movement, or impact assessment. Route single-stage tasks directly to their specialist skill.

١٨ أغسطس ٢٠٢٦
عرض 8 من أصل ٨٧ skills مجمعة.
عرض ٢ من أصل ٢ مستودعات
تم تحميل كل المستودعات