用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/420company/artemis --skill review-attack-surface命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
This skill should be used when the user asks to "call the Spotify Ads API", "create a Spotify ad campaign", "manage Spotify ads", "pull Spotify ad reports", "set up ad sets or ads", "upload ad assets", "target audiences on Spotify", "check campaign status", "get ad account info", "look up API schema or fields", "check what targeting options exist", or asks about Spotify advertising endpoints, request/response formats, enum values, or authentication.
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and infrastructure-as-code (Terraform, Pulumi). Use for any Cloudflare development task. Biases towards retrieval from Cloudflare docs over pre-trained knowledge.
Accessibility audit skill for scanning, fixing, and verifying WCAG 2.2 Level A and AA compliance across React, Next.js, Vue, Angular, Svelte, and plain HTML codebases. Use when auditing accessibility, fixing a11y violations, checking color contrast, generating compliance reports, or integrating accessibility checks into CI/CD pipelines.
基于 SOC 职业分类
正在显示 SKILL.md
| name | review-attack-surface |
| disable-model-invocation | true |
| argument-hint | [organization_name] [focus: findings|lookalikes|all] |
| description | Review external attack surface using Zscaler EASM findings, exposed services, and lookalike domains. |
Review attack surface: $ARGUMENTS
easm_list_organizations()
```text
If an organization was specified, find its ID. Otherwise, use the primary organization.
## Step 2: Retrieve Findings
```text
easm_list_findings(organization_id="<id>")
```text
## Step 3: Analyze Findings by Severity
Categorize findings:
- **Critical**: Exploitable vulnerabilities, exposed admin panels, default credentials
- **High**: Exposed services (RDP, SSH, databases), expired certificates
- **Medium**: Misconfigurations, information disclosure
- **Low**: Best-practice improvements
## Step 4: Check Lookalike Domains
```text
easm_list_lookalike_domains(organization_id="<id>")
```text
Flag domains that could be used for phishing or brand impersonation.
## Step 5: Get Detailed Finding Info
For critical/high findings:
```text
easm_get_finding(finding_id="<id>")
```text
## Step 6: Present Report
```text
External Attack Surface Report
================================
Organization: <name>
Scan date: <date>
FINDINGS SUMMARY:
Critical: X
High: Y
Medium: Z
Low: W
CRITICAL FINDINGS:
1. <finding_type>: <asset>
Risk: <description>
Remediation: <steps>
HIGH FINDINGS:
1. ...
LOOKALIKE DOMAINS:
- <domain> (similarity: X%) -- potential phishing
- <domain> (similarity: Y%) -- registered <date>
PRIORITY REMEDIATION:
1. <most urgent action>
2. <next action>
```text