用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/aibot88/sec_skill_store --skill vuln-scan命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
Guides the creation of agile user stories and Gherkin feature files. Use when the user wants to create a user story, write acceptance criteria, define Gherkin scenarios, or author BDD feature files. This should trigger for requests such as Create a user story; Write a user story; I need to write a user story. Part of cursor-rules-java project
Guía técnica completa para integrar 250+ servicios externos con agentes IA usando Composio. Cubre instalación, autenticación OAuth, gestión de herramientas, triggers y flujos multi-servicio.
Facilitates conversational discovery to create Architectural Decision Records (ADRs) for non-functional requirements using the ISO/IEC 25010:2023 quality model. Use when the user wants to document quality attributes, NFR decisions, security/performance/scalability architecture, or design systems with measurable quality criteria. This should trigger for requests such as Create ADR for Non-functional requirements; Document Non-functional requirements; Capture Non-functional requirements; Generate Non-functional requirements in an ADR. Part of cursor-rules-java project
基于 SOC 职业分类
正在显示 SKILL.md
| name | vuln-scan |
| description | Analyze dependency or ecosystem risk and produce remediation and advisory packets. |
Review one dependency surface or project scope and produce a bounded security packet. This skill is for operator-facing risk analysis, remediation planning, and advisory drafting. It is not a license to run arbitrary destructive scans.
Keep the output practical: what is affected, how serious it is, what to do next, and whether a public advisory is justified.
needs_more_evidence, needs_human, or
do_not_publish_advisory when exposure, affected versions, or disclosure
posture cannot be verified.Scan runner:
dependency_inventory: affected components and versions.advisories: findings with severity, exposure, and evidence.remediation_plan: concrete next actions.operator_summary: concise decision-ready summary.Advisory runner:
advisory_draft: public or maintainer-facing advisory text.maintainer_summary: concise summary for repo owners.disclosure_checklist: what to verify before public release.target (required): repo, lockfile, package set, or ecosystem slice.objective (optional): what the operator wants from this scan.scan_context (optional): known packages, incidents, or prior findings.advisories (optional): structured findings from the scan runner.remediation_plan (optional): structured remediation plan for the advisory pass.