Skip to main content

这个仓库中的 skills

aibot88/sec_skill_store - 第 20 页

SkillsMP 已收集 aibot88/sec_skill_store 中的 2,449 个 Skill。打开任一 Skill 可查看来源和详情。

aibot88/sec_skill_store

已展示 40 / 2,449 个已收集 Skill。

职业分类
信息安全分析师
描述

Detects stack and heap buffer overflow vulnerabilities in binary code by identifying unsafe memory operations. Use when analyzing buffer handling, string manipulation functions, or investigating memory corruption vulnerabilities.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detects OS command injection vulnerabilities by identifying unsafe system/popen/exec calls with user-controlled input. Use when analyzing command execution, shell operations, or investigating potential command injection points.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Identifies unreachable functions, unused variables, and abandoned code in binary programs. Use when optimizing binary size, analyzing code coverage, or investigating abandoned functionality.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detects information disclosure vulnerabilities including sensitive data in logs, error message exposure, and memory leaks. Use when analyzing logging practices, error handling, or investigating data leakage issues.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detects various injection vulnerabilities including SQL injection, LDAP injection, XPath injection, and code injection. Use when analyzing database queries, dynamic code generation, or investigating injection attacks.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detects integer overflow and underflow vulnerabilities in arithmetic operations used for buffer sizing or allocation. Use when analyzing calculations, size computations, or investigating integer wraparound issues.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detects null pointer dereference vulnerabilities by identifying unchecked pointer usage and missing validation. Use when analyzing pointer operations, input validation, or investigating crash vulnerabilities.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detects privilege escalation vulnerabilities including setuid/setgid abuse, permission check bypasses, and unsafe privilege management. Use when analyzing setuid binaries, permission checks, or investigating privilege escalation paths.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Detects race condition vulnerabilities including TOCTOU, double-checked locking issues, and shared state problems. Use when analyzing concurrent operations, file access patterns, or investigating timing-related vulnerabilities.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Detects suspicious use of assertions for security checks that can be disabled in production builds. Use when analyzing assertion usage, security checks, or investigating assert-related vulnerabilities.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Detects type confusion vulnerabilities by identifying unsafe type casts, vtable corruption, and polymorphism issues. Use when analyzing object-oriented code, type casting, or investigating C++ memory safety issues.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Detects use-after-free vulnerabilities by identifying pointer dereferences after memory deallocation. Use when analyzing memory management, cleanup code, or investigating dangling pointer issues.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Create detection rules and hunting queries from malware analysis findings. Use when you need to write Sigma rules for SIEM, Suricata rules for network IDS, defang IOCs for safe sharing, or convert analysis findings into actionable detection content for SOC…

原文语言:英语

更新
职业分类
信息安全分析师
描述

IDS/IPS detection content for a CVE — Snort/Suricata-compatible rules, YARA signatures, ProjectDiscovery Nuclei templates, traffic-filter rules. Capability-aware: skips families when the binary is not installed (no Snort = no Snort output). Use when deploying…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Detects SpecWeave context and provides workflow documentation for available commands. Use when learning SpecWeave commands, understanding available slash commands (/sw:increment, /sw:do, /sw:progress, /sw:done), or getting workflow guidance. Explains command…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Production-grade API design patterns for REST, GraphQL, gRPC, and tRPC. Covers API architecture, OpenAPI/Swagger specs, versioning/deprecation, authentication/authorization, rate limiting, pagination, error models, contract testing, and developer…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Modern web auth implementation (better-auth, Lucia, NextAuth/Auth.js, Clerk, Supabase Auth). Trigger when the user wants to add login, signup, sessions, OAuth, magic links, 2FA, or when existing auth code is detected to audit or migrate.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Master skill for Backend Integration (Supabase) and API handling. Covers database schema, authentication, and SQL.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Internal skill used by dev-implement during Phase 5 of /dev workflow. NOT user-facing - should only be invoked by dev-ralph-loop inside each implementation iteration. Handles Task agent spawning with TDD enforcement and two-stage review (spec compliance +…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Intercepts and audits dependency installations (pip, npm, go) before they execute. Validates package identity, checks vulnerabilities, flags supply-chain risk signals, and enforces hash pinning in lockfiles.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Package and dependency management patterns across ecosystems (npm, pip, cargo, maven). Covers lockfiles, semantic versioning, dependency security scanning, update strategies, monorepo workspaces, transitive dependencies, and avoiding dependency hell.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Creates or audits Dockerfiles to achieve Docker Hub Health Score grade A. Enforces non-root user, minimal base images, supply chain attestations, and zero fixable CVEs.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Développement d'APIs Node.js avec Express, middleware, routing, gestion d'erreurs, authentification et bonnes pratiques de conception. Se déclenche avec "Express", "Express.js", "middleware Express", "Node.js API", "router Express".

原文语言:法语

更新
职业分类
软件开发工程师
描述

Automated software development agent using ChatDev 2.0 and GLM-5. Discovers topics from GitHub Trending, CVE databases, and security news → generates code with 7-agent ChatDev team → tests automatically → publishes to GitHub. Self-correction loop (error → fix…

原文语言:韩语

更新
职业分类
软件开发工程师
描述

Gate 6 of frontend development cycle — ensures Core Web Vitals compliance, Lighthouse performance score > 90, and bundle size within budget.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Watchdog automatico per file critici: avvisa prima di modificare .env, migrations, CI, secrets. Usa questa skill quando l'utente vuole protezione automatica, o dice guard, watchdog, proteggi file, guardia, sentinel, file critici.

原文语言:意大利语

更新
职业分类
软件开发工程师
描述

Mandatory skill for creating and maintaining Helm charts following Lerian conventions. Enforces standardized chart structure, values organization, template patterns, security defaults, and dependency management.

原文语言:英语

更新
职业分类
软件开发工程师
描述

Delegate QAQC and review tasks to Google Gemini CLI using markdown file handoff pattern. Write review request to REVIEW.md, Gemini analyzes, outputs findings to FINDINGS.md. Use for code review, security audits, documentation review, large context analysis.…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Delegate testing, QA, and code review tasks to Opencode CLI using Kimi K2.5 model via markdown file handoff. Write test request to TASK.md, Opencode with Kimi K2.5 generates tests/reviews, outputs to OUTPUT.md. Use for test generation, QA verification, edge…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Développement Java avec Spring Boot, Spring Security et l'écosystème Spring. Se déclenche avec "Java", "Spring Boot", "Spring", "JPA", "Hibernate", "Maven", "Gradle", "Spring Security", "microservices Java".

原文语言:法语

更新
职业分类
软件开发工程师
描述

Multi-tenant development cycle orchestrator following Ring Standards. Auto-detects service stack (PostgreSQL, MongoDB, Redis, RabbitMQ, S3) and executes gate-based implementation using tenantId from JWT for database-per-tenant isolation via the lib-commons v5…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Configuration Nginx — reverse proxy, SSL/TLS, load balancing, caching et security headers. Se déclenche avec "Nginx", "nginx.conf", "reverse proxy", "SSL Nginx", "load balancer Nginx".

原文语言:法语

更新
职业分类
软件开发工程师
描述

Implémentation d'OAuth2, OpenID Connect, JWT et gestion des tokens pour sécuriser des APIs et applications web. À utiliser quand l'utilisateur configure de l'authentification, des tokens JWT, ou intègre un identity provider. Se déclenche aussi avec "OAuth2",…

原文语言:法语

更新
职业分类
信息安全分析师
描述

Vérifie un projet contre le OWASP Top 10 et propose des remédiations. À utiliser pour vérifier la conformité OWASP. Se déclenche avec "OWASP", "top 10", "failles web", "sécurité web", "A01 broken access", "injection", "vérifier OWASP".

原文语言:法语

更新
职业分类
信息安全分析师
描述

Guide méthodologique pour tests d'intrusion et évaluation de sécurité. À utiliser pour préparer ou conduire un pentest. Se déclenche avec "pentest", "test d'intrusion", "test de pénétration", "hacking éthique", "red team", "bug bounty", "surface d'attaque".

原文语言:法语

更新
职业分类
软件开发工程师
描述

Readiness implementation orchestrator for Lerian services. Drives a 12-gate cycle that detects stack, audits existing /readyz compliance, dispatches language-specific engineers (Go / TypeScript / Next.js) to implement the canonical /readyz contract,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Détecte les secrets, clés API et credentials exposés dans le code. À utiliser pour vérifier qu'aucun secret n'est dans le code. Se déclenche avec "secrets", "clé API exposée", "credential leak", "mot de passe dans le code", "token exposé", ".env", "secret…

原文语言:法语

更新
职业分类
信息安全分析师
描述

Audit de sécurité complet d'une application ou d'un code source. À utiliser quand l'utilisateur veut vérifier la sécurité de son projet. Se déclenche avec "audit sécurité", "security audit", "vérifier la sécurité", "est-ce que mon code est sécurisé", "analyse…

原文语言:法语

更新
职业分类
信息安全分析师
描述

Audit de sécurité de smart contracts Solidity et blockchain. Se déclenche avec "smart contract", "Solidity", "audit blockchain", "vulnérabilité smart contract", "reentrancy", "ERC-20", "ERC-721", "Web3 security".

原文语言:法语

更新
职业分类
数据库架构师
描述

Guide pour écrire des requêtes SQL et concevoir des schémas SQLite avec les bonnes pratiques. À utiliser quand l'utilisateur travaille avec SQLite, écrit des requêtes SQL ou conçoit des schémas de base de données. Se déclenche aussi avec "requête SQL",…

原文语言:法语

更新
已展示 40 / 2,449 个已收集 Skill。