com um clique
trailofbits-security
Use when CodeQL/Semgrep 静态分析,漏洞检测 - 驱动安全审计、内核模块漏洞扫描。
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Menu
Use when CodeQL/Semgrep 静态分析,漏洞检测 - 驱动安全审计、内核模块漏洞扫描。
Instalar com Codex ou Claude Copie este prompt, cole no Codex, Claude ou outro assistente e deixe que ele revise a página da skill e instale para você.
Baseado na classificação ocupacional SOC
Find, compare, and install agent skills across ClawHub and Skills.sh when the user needs new capabilities, better workflows, stronger tools, or safer alternatives. Use when (1) they ask how to do something, how to improve or automate it, or what to install; (2) a skill could extend the agent, replace a weak manual approach, or close a capability gap; (3) you need the best-fit option, not just a direct answer.
Use when 安装、配置或操作 oh-my-opencode - 多 agent 编排、ultrawork 模式、后台任务管理
Remote-control tmux sessions for interactive CLIs - OpenCode 多会话编排、长时任务监控、远程研发持久化
When user asks to summarize text, articles, documents, meetings, emails, YouTube transcripts, books, PDFs, reports, conversations, or any long content. Also handles bullet points, key takeaways, action items, TL;DR, ELI5, executive summaries, chapter summaries, comparison summaries, translation summaries, thread summaries, and custom-length summaries. 20-feature AI summarizer with multiple formats, languages, and export options. All processing happens locally — NO external API calls, NO network requests, NO data sent to any server.
Use when 长任务规划持久化,上下文压缩不丢失 - 驱动开发、内核移植等长周期任务的进度管理。
Use when 跨会话记住调试经验、编译错误修正 - 记录交叉编译错误、驱动加载失败、设备树解析错误等常见问题的解决方案。
| name | trailofbits-security |
| description | Use when CodeQL/Semgrep 静态分析,漏洞检测 - 驱动安全审计、内核模块漏洞扫描。 |
| tier | 第二梯队 |
| source | GitHub (Trail of Bits) |
编号: 12 梯队: 第二梯队 来源: GitHub (Trail of Bits)
内核/驱动代码安全漏洞可能导致提权、DoS。Trail of Bits 是顶级安全研究团队。
CodeQL/Semgrep 静态分析,漏洞检测
嵌入式场景: 驱动安全审计、内核模块漏洞扫描。
GitHub: 从 trailofbits/skills 仓库安装
运行 CodeQL/Semgrep 静态分析,检测缓冲区溢出、use-after-free、整数溢出、竞态条件等安全漏洞。生成漏洞报告。
驱动安全审计、内核模块漏洞扫描。
参考 opencode-skill-list.md 获取完整清单和学习路径。