en un clic
Safety-Protection-Agent
Safety-Protection-Agent contient 3 skills collectées depuis Heyu2002, avec une couverture métier par dépôt et des pages de détail sur le site.
Skills dans ce dépôt
Guide Codex through defensive red-team validation for SPA or other MCP-compatible agents. Use when the user wants to evaluate agent self-protection, prompt injection resistance, hostile context handling, tool overreach, MCP tool misuse, canary or secret exfiltration, sensitive tool access, system prompt disclosure, memory poisoning, sandbox behavior, published agent API safety, or Markdown reports produced by spa-agent-lab-mcp. Also use for Chinese requests about agent 自身安全, 红队测试, 提示注入, 工具越权, 敏感工具, 金丝雀外发, 系统提示词泄露, or agent 防护能力.
Guide authorized web security assessment when the agent or host cannot directly access the target because internal and external networks are disconnected, isolated, air-gapped, intranet-only, VPN-only, jump-host-only, no-route, 内外网不互通, 内网隔离, 网络隔离, 无法直连, 无法访问, or when the user provides HAR, curl, HTTP transcripts, Postman/Burp exports, source bundles, logs, or screenshots instead of live access. Use for offline evidence-driven vulnerability discovery, internal-runner probe planning, report generation, and remediation guidance.
Guide an agent through authorized website vulnerability discovery. Use when the user provides a website, web app, lab URL, target scope, or browser-accessible application and asks to find, validate, exploit safely, confirm, or report possible web vulnerabilities including auth issues, access control, injection, XSS, redirects, weak sessions, sensitive data exposure, security headers, rate limiting, CORS, cookie flags, TLS, or browser-observable flaws.