Skip to main content

Skills dans ce dépôt

yanacuti1121/Yana-AI - Page 34

SkillsMP a collecté 1 566 skills depuis yanacuti1121/Yana-AI. Ouvrez un skill pour examiner sa source et ses détails.

yanacuti1121/Yana-AI

Affichage de 40 skills collectés sur 1 566.

métier
Analystes en sécurité de l'information
description

Test web applications for HTTP Host header injection vulnerabilities to identify password reset poisoning, web cache poisoning, SSRF, and virtual host routing manipulation risks.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Test JWT implementations for critical vulnerabilities including algorithm confusion, none algorithm bypass, kid parameter injection, and weak secret exploitation to achieve authentication bypass and privilege escalation.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Identifying sensitive data exposure vulnerabilities including API key leakage, PII in responses, insecure storage, and unprotected data transmission during security assessments.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Test web applications for XML injection vulnerabilities including XXE, XPath injection, and XML entity attacks to identify data exposure and server-side request forgery risks.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Tests web applications for Cross-Site Scripting (XSS) vulnerabilities by injecting JavaScript payloads into reflected, stored, and DOM-based contexts to demonstrate client-side code execution, session hijacking, and user impersonation. The tester identifies…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Identifying and validating cross-site scripting vulnerabilities using Burp Suite's scanner, intruder, and repeater tools during authorized security assessments.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Discovering and exploiting XML External Entity injection vulnerabilities to read server files, perform SSRF, and exfiltrate data during authorized penetration tests.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Assessing JSON Web Token implementations for cryptographic weaknesses, algorithm confusion attacks, and authorization bypass vulnerabilities during security engagements.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Tests authentication and authorization mechanisms in mobile application APIs to identify broken authentication, insecure token management, session fixation, privilege escalation, and IDOR vulnerabilities. Use when performing API security assessments against…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Tests OAuth 2.0 and OpenID Connect implementations for security flaws including authorization code interception, redirect URI manipulation, CSRF in OAuth flows, token leakage, scope escalation, and PKCE bypass. The tester evaluates the authorization server,…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Test and validate ransomware recovery procedures including backup restore operations, RTO/RPO target verification, recovery sequencing, and clean restore validation to ensure organizational resilience against destructive ransomware attacks.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Tests WebSocket API implementations for security vulnerabilities including missing authentication on WebSocket upgrade, Cross-Site WebSocket Hijacking (CSWSH), injection attacks through WebSocket messages, insufficient input validation, denial-of-service via…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Expert guidance for developing with the tinystruct Java framework. Use when working on the tinystruct codebase or any project built on tinystruct — including creating Application classes, @Action-mapped routes, unit tests, ActionRegistry, HTTP/CLI dual-mode…

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

Expert tmux session, window, and pane management for terminal multiplexing, persistent remote workflows, and shell scripting automation.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Token budget analytics and ROI scoring for AI agent actions. Track token cost per fix, detect wasteful loops, auto-route to fast tier when burn rate is too high. Integrates with token-budget-guard.sh hook. Triggered by /cost-report, "how much did that cost",…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Threat actor infrastructure tracking involves monitoring and mapping adversary-controlled assets including command-and-control (C2) servers, phishing domains, exploit kit hosts, bulletproof hosting, a

Langue du texte source : anglais

mis à jour
métier
Analystes financiers et en placements
description

Paste your trading history (CSV / broker export / list of trades) and AI extracts hidden behavioral biases, implicit rules, and compares your actual behavior vs an ideal shadow strategy. Inspired by HKUDS/Vibe-Trading Shadow Account Analysis (MIT).

Langue du texte source : vietnamien

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

Traefik cloud-native ingress router with automatic TLS, dynamic configuration, middleware chains, and Kubernetes IngressRoute CRDs. Sources: traefik/traefik (MIT).

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Triages security alerts in Splunk Enterprise Security by classifying severity, investigating notable events, correlating related telemetry, and making escalation or closure decisions using SPL queries and the Incident Review dashboard. Use when SOC analysts…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Performs initial triage of security incidents to determine severity, scope, and required response actions using the NIST SP 800-61r3 and SANS PICERL frameworks. Classifies incidents by type, assigns priority based on business impact, and routes to appropriate…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Classify and prioritize security incidents using structured IR playbooks to determine severity, assign response teams, and initiate appropriate response procedures.

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Triage and prioritize vulnerabilities using CISA's Stakeholder-Specific Vulnerability Categorization (SSVC) decision tree framework to produce actionable remediation priorities.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Twirp lightweight RPC over HTTP/1.1 with Protobuf or JSON transport. Service routing, error codes, middleware hooks, and no-proxy deployment for simple agent-to-agent calls. Sources: twitchtv/twirp (Apache-2.0).

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Type-safe API contract patterns. tRPC end-to-end typed procedures, ts-rest shared contract definitions, zod-to-openapi spec generation, Zodios Axios client, and contract-first development workflow. Sources: trpc/trpc, ts-rest/ts-rest,…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Write precise TypeScript — generic constraints, conditional types, mapped types, template literal types, branded/nominal types, type narrowing, satisfies operator, and utility type composition. Use when asked about "TypeScript generics", "conditional type",…

Langue du texte source : anglais

mis à jour
métier
Concepteurs web et d'interfaces numériques
description

Design a complete typography system — font pairing, type hierarchy, micro-typography (line-height, letter-spacing, measure), web font performance (font-display, preload, system stacks), and Vietnamese diacritic considerations. Use when the user asks to…

Langue du texte source : anglais

mis à jour
métier
Concepteurs web et d'interfaces numériques
description

Diagnose and redesign an existing UI that looks dated, cluttered, or inconsistent. Produces a structured critique and a revised implementation. Use when the user asks to "redesign this page", "this UI looks bad", "make it modern", "clean this up", or "the…

Langue du texte source : anglais

mis à jour
métier
Concepteurs web et d'interfaces numériques
description

Design all 7 UI states for any data-dependent view: empty, loading, skeleton, partial, complete, error, offline. Use when asked about "loading state", "skeleton screen", "error message", "empty state", "optimistic UI", "what happens while data loads", or…

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

UID/GID privilege dropping for safe agent subprocess execution. setuid/setgid before exec, running commands as nobody/unprivileged user, Node.js uid/gid options on spawn, and preventing privilege re-escalation. Sources: stephenmathieson/node-uid, Linux…

Langue du texte source : anglais

mis à jour
métier
Analystes en assurance qualité des logiciels et testeurs
description

Write effective unit tests — Arrange-Act-Assert structure, test boundary selection, mocking strategy, test doubles (spy/stub/mock/fake), parameterized tests, snapshot pitfalls, test naming, and Vitest/Jest configuration. Use when asked about "unit test",…

Langue du texte source : anglais

mis à jour
métier
Administrateurs de réseaux et de systèmes informatiques
description

Rootless sandbox via bubblewrap (bwrap). No-root container isolation using user namespaces, read-only bind mounts, tmpfs overlays, seccomp profiles, and capability dropping. Ideal for GitHub Codespaces. Sources: containers/bubblewrap.

Langue du texte source : anglais

mis à jour
métier
Concepteurs web et d'interfaces numériques
description

Evaluate a UI against Nielsen's 10 Usability Heuristics — score each heuristic, flag violations with severity ratings, and produce a prioritized fix list. Use when the user asks for a "UX review", "usability audit", "heuristic evaluation", or "why is this UI…

Langue du texte source : anglais

mis à jour
métier
Analystes en sécurité de l'information
description

Validate backup integrity through cryptographic hash verification, automated restore testing, corruption detection, and recoverability checks to ensure backups are reliable for disaster recovery and ransomware response scenarios.

Langue du texte source : anglais

mis à jour
métier
Analystes financiers et en placements
description

Buffett 6-gate checklist for any stock or company. Forces a hard pass/fail verdict with moat scoring, management trust rating, and margin of safety. No hedging, no "it depends". Inspired by ai-berkshire (MIT).

Langue du texte source : Plusieurs langues

mis à jour
métier
Développeurs de logiciels
description

Manage Venice API keys. Covers GET/POST/PATCH/DELETE /api_keys, GET /api_keys/{id}, GET /api_keys/rate_limits, GET /api_keys/rate_limits/log, the two-step /api_keys/generate_web3_key wallet flow, INFERENCE vs ADMIN key types, and per-key consumption limits…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

High-level map of the Venice.ai API - base URL, authentication modes, endpoint categories, response headers, pricing model, error shape, and versioning. Load this first when starting any Venice integration.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Async music / audio-track generation via Venice. Covers the /audio/quote + /audio/queue + /audio/retrieve + /audio/complete lifecycle, lyrics vs instrumental, voice selection, duration, language, speed, model capability probing, and webhook-free polling.

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Generate speech from text via POST /audio/speech. Covers TTS models (Kokoro, Qwen 3, xAI, Inworld, Chatterbox, Orpheus, ElevenLabs Turbo, MiniMax, Gemini Flash), voices per family, output formats (mp3/opus/aac/flac/wav/pcm), streaming, prompt/emotion styling,…

Langue du texte source : anglais

mis à jour
métier
Développeurs de logiciels
description

Transcribe audio files to text via POST /audio/transcriptions. Covers supported models (Parakeet, Whisper, Wizper, Scribe, xAI STT), supported formats (wav/flac/m4a/aac/mp4/mp3/ogg/webm), response formats (json/text), timestamps, and language hints.…

Langue du texte source : anglais

mis à jour
Affichage de 40 skills collectés sur 1 566.