Skip to main content

Vulnetix/pix-ai-coding-assistant

SkillsMP는 Vulnetix/pix-ai-coding-assistant에서 18개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
18
GitHub 스타
9
GitHub 포크
1

AI 어시스턴트로 설치

이 프롬프트를 복사해 사용 중인 AI 어시스턴트에 입력하세요.

이 저장소의 Agent Skills 설치를 도와주세요: https://github.com/Vulnetix/pix-ai-coding-assistant
먼저 출처, SKILL.md 및 관련 파일을 확인하고 설치 가능한 Skill 목록을 보여주세요. 제가 선택하면 해당 Skill의 전체 디렉터리를 현재 프로젝트에 설치하고 필요한 파일이 모두 있는지 확인해 주세요.

수집된 skill 18개 중 18개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Post-fix verification — re-scan the repo, gate on `--exploits weaponized --severity high`, recheck the specific CVE against the new installed version, write the verdict to `.vulnetix/memory.yaml`. Use when confirming a fix landed, validating a version bump…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Concrete remediation proposal with Safe Harbour confidence — version bump, inline as first-party code, patch, workaround, or advisory. Use when applying a fix for a triaged CVE, evaluating fix-type trade-offs across registry / source / distro patches,…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Proactive secure-coding coach scoped to the file or topic you are working on — surfaces relevant SAST rule IDs, CWE patterns, language-specific PASS/FAIL code snippets. Use when about to write auth, crypto, SQL, deserialization, file-handling, or template…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Typosquat and malicious-package detection across installed dependencies (or a single prospective addition) — cross-checks AI-malware family intelligence, package-name similarity to known popular packages, low maintainer-health signals. Use when auditing a…

원문 언어: 영어

업데이트
직업 분류
컴퓨터 시스템 분석가
설명

Dockerfile / Containerfile / compose analysis plus optional Trivy / Grype / Syft composition when those binaries are present. Use when reviewing a Dockerfile PR, gating `docker build`, building an image SBOM, evaluating base-image risk, or auditing a registry…

원문 언어: 영어

업데이트
직업 분류
컴퓨터 시스템 분석가
설명

Show what this repository has already decided about its vulnerabilities, read from the durable record rather than by scanning again — open versus resolved, the decision taken on each, and what is still waiting. Use when picking up triage after a break,…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Dependency-conflict resolution when a `fix` version bump fails — diagnose the peer-dep tree, find a compatible safe version set, propose package-manager overrides (`overrides`/`resolutions`/`replace`/`[patch]`), fall back to safe-harbour inline patching. Use…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Work through which package to add for a capability, and what each option costs — maintenance, licence, bundle weight, transitive risk, and whether the platform already does it. Use when someone needs a library for a job and has not picked one yet, when…

원문 언어: 영어

업데이트
직업 분류
컴퓨터 시스템 분석가
설명

IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying…

원문 언어: 영어

업데이트
직업 분류
컴퓨터 시스템 분석가
설명

End-of-life detection for runtimes (Node, Python, Java, Go, .NET) and key packages — surfaces past-EOL items, items reaching EOL within 90 days, and EOL base images for containers. Use when planning a runtime upgrade, auditing for unsupported versions, gating…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 품질 보증 분석가·테스터
설명

Generate a runnable exploit-validation command (Nuclei template, Metasploit module hint, AI-assisted Python script, or curl-based PoC) against a user-specified authorised target. Use when validating that a fix actually closed the vulnerability path,…

원문 언어: 영어

업데이트
직업 분류
컴퓨터 시스템 분석가
설명

Terraform / OpenTofu / Nix / k8s manifest misconfiguration detection — open security groups, missing encryption, public S3/GCS, IAM wildcards, plaintext secrets, missing tags. Use when reviewing an IaC PR, gating `terraform apply` / `tofu apply`, auditing…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Package license analysis — detect copyleft conflicts against a permissive policy, surface AGPL / SSPL / GPL contaminants, output SPDX SBOM with per-package license findings. Use when auditing a release for license compliance, vetting a new dependency's…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Answer whether a specific advisory reaches anything in THIS repository — which manifest declares the package, at what version, whether the version is in range, and whether the vulnerable code is reachable. Use when someone asks "does CVE-… affect us", when…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 품질 보증 분석가·테스터
설명

Static application security testing (SAST) for changed source files — Vulnetix's built-in rule set plus optional Semgrep augmentation when `.semgrep` config is present. Use when reviewing a PR for code-level vulnerabilities, scanning a feature branch before…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Generate CycloneDX 1.7 and/or SPDX 2.3 SBOMs for the repo, optionally cosign-signed, optionally cross-validated against syft output. Use when producing an SBOM for compliance, attaching to a release artefact, integrating with an SBOM registry, or satisfying a…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Hardcoded-secret detection — AWS keys, GitHub PATs, Slack tokens, Stripe keys, generic high-entropy strings. Pre-commit (`--staged-only`), explicit paths, or full repo. Use when guarding `git commit`, auditing a repo for leaked credentials, validating no…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Generate OpenVEX / CycloneDX VEX attestations from `.vulnetix/memory.yaml` triage decisions, optionally sign with cosign, optionally upload to Vulnetix and post to a GitHub PR. Use when documenting triage decisions for supply-chain consumers, attaching VEX to…

원문 언어: 영어

업데이트
수집된 skill 18개 중 18개를 표시합니다.