Skip to main content

这个仓库中的 skills

aibot88/sec_skill_store - 第 52 页

SkillsMP 已收集 aibot88/sec_skill_store 中的 2,449 个 Skill。打开任一 Skill 可查看来源和详情。

aibot88/sec_skill_store

已展示 40 / 2,449 个已收集 Skill。

职业分类
信息安全分析师
描述

Performs advanced SAST (Static Application Security Testing) and compliance analysis on Pull Request diffs. Identifies real security vulnerabilities, secrets, and regulatory compliance violations (GDPR, HIPAA, SOC2, PCI-DSS) by analyzing only changed code.…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Walk a security team member through allocating a CVE for an <tracker> tracking issue. Prints the ASF Vulnogram allocation URL and a CVE-ready title (the issue title stripped of redundant `<vendor>: <product>:` (e.g. `Apache Airflow:`), `[ Security Report ]`,…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Audit de sécurité des dépendances — détection de vulnérabilités connues, mises à jour critiques et gestion du cycle de vie des packages. À utiliser quand l'utilisateur veut vérifier la sécurité de ses dépendances, mettre à jour des packages vulnérables ou…

原文语言:法语

更新
职业分类
信息安全分析师
描述

SEOcrawler security vulnerability scanner and hardening specialist for comprehensive security audits.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Sempre considera vetores OWASP top-10 ao escrever/revisar código

原文语言:葡萄牙语

更新
职业分类
信息安全分析师
描述

Adversarial defense layer for the mortgage plugin — protects against prompt injection, system prompt extraction, PII leakage, workflow bypass, and social engineering attacks.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Sécurisation d'agents IA contre injections, abus et fuites de données. Se déclenche avec "sécurité agent", "agent security", "prompt injection", "jailbreak", "agent abuse", "guardrails", "safe agent", "sécuriser mon agent", "agent en production sécurisé".

原文语言:法语

更新
职业分类
其他业务运营专家
描述

Plan de réponse aux incidents de sécurité — préparation, détection, containment, éradication, recovery et lessons learned. Se déclenche avec "incident response", "plan de réponse", "breach", "compromission", "réponse à incident", "CSIRT".

原文语言:法语

更新
职业分类
信息安全分析师
描述

Merge two <tracker> tracking issues that describe the same root-cause vulnerability (typically discovered independently by two reporters, arriving via different channels), preserving every reporter's credit, every mailing-list thread reference, and every…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Attempt to fix a security issue tracked in <tracker> by implementing the change in a public <upstream> PR. Runs the security-issue-sync skill first to reconcile the issue's state, then analyses the discussion to decide whether the issue is easily fixable…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Open one or more `<tracker>` tracking issues from a markdown file containing a batch of security findings (typically the output of an AI security review or a third-party scanner). Each finding in the file becomes one tracker, landing in the `Needs triage`…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Open a tracking issue in <tracker> for a security-relevant fix that has already been opened (or merged) as a public PR in <upstream>, in the case where there is no inbound `<security-list>` report. The tracker lands in the `Assessed` board column (the…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Scan <security-list> for reports that have not yet been copied into <tracker> as tracking issues, present the proposed imports to the user, and — defaulting to *import unless the user rejects upfront* — create the tracking issues with the `Needs triage`…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Close an `<tracker>` tracking issue as invalid: apply the `invalid` label, remove the scope label, post a short closing comment, archive the item from the project board, and — for trackers imported from `<security-list>` — draft a polite-but-firm reply to the…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Synchronize a security issue in <tracker> with the state of its GitHub discussion, the <security-list> mailing thread, and any <upstream> PRs that fix it. The skill gathers all relevant signals, proposes label, milestone, assignee, field and draft-email…

原文语言:英语

更新
职业分类
信息安全分析师
描述

For each open `<tracker>` issue carrying the `needs triage` label, read body + comments and classify the candidate disposition into one of five classes: VALID / DEFENSE-IN-DEPTH / INFO-ONLY / INVALID / PROBABLE-DUP. On user confirmation, posts a…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Plans security penetration tests for web applications. Analyzes codebase, API routes, auth implementation, and infrastructure config to generate comprehensive pentest plans. For authorized testing only.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Automated PII detection and redaction for client data protection. Scans outputs, logs, artifacts, and communications for sensitive data before external exposure. Derived from ruflo agent-security-manager + @claude-flow/aidefence patterns. Use when: generating…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security anti-patterns — localStorage token storage (XSS risk), trusting client-side authorization checks, reflecting full error details to clients, blacklist vs whitelist input validation, using npm install instead of npm ci in CI pipelines.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security-focused code review that emits a numeric composite score (0.0–1.0) suitable for the evolve-loop Builder self-review convergence loop

原文语言:英语

更新
职业分类
信息安全分析师
描述

Security patterns for Web3 and blockchain applications — Solana wallet signature verification, transaction validation, smart contract interaction security, and checklist for DeFi/NFT features.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Automatisation d'audits de sécurité incluant scanning, reporting, intégration CI/CD et remediation tracking. Se déclenche avec "audit automatisé", "security scanning", "SAST", "DAST", "Trivy", "Snyk", "audit CI/CD"

原文语言:法语

更新
职业分类
信息安全分析师
描述

Guide pour analyste SOC — triage d'alertes, investigation, SIEM, indicateurs de compromission et playbooks de réponse. Se déclenche avec "SOC", "analyste SOC", "SIEM", "IoC", "incident de sécurité", "triage sécurité".

原文语言:法语

更新
职业分类
信息安全分析师
描述

Run composable security analysis across binaries, prompts, traces, and policies.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Analyze codebase architecture to generate a STRIDE-based threat model with data flow diagrams, trust boundaries, prioritized threats, and mitigations. Compatible with Microsoft Threat Modeling Tool concepts. Use when asked to "threat model", "security…

原文语言:英语

更新
职业分类
信息安全分析师
描述

Modélisation des menaces pour applications et systèmes — identification des surfaces d'attaque, classification STRIDE, arbres d'attaque et stratégies de mitigation. À utiliser quand l'utilisateur veut sécuriser une architecture, identifier des vulnérabilités…

原文语言:法语

更新
职业分类
信息安全分析师
描述

نظام إدارة واكتشاف ومعالجة الثغرات الأمنية. استخدم هذا الـ skill عند: فحص الثغرات، إدارة نقاط الضعف، اختبار الاختراق، تقييم المخاطر الأمنية، OWASP compliance، إدارة الأحداث الأمنية (SIEM)، استجابة الحوادث، تحديثات أمنية، مسح الشبكة، أو أي مهمة تتعلق بالأمن…

原文语言:阿拉伯语

更新
职业分类
信息安全分析师
描述

Architecture Zero Trust — never trust always verify, micro-segmentation réseau, approche identity-centric et accès conditionnel. Se déclenche avec "Zero Trust", "zero trust architecture", "never trust", "micro-segmentation", "BeyondCorp".

原文语言:法语

更新
职业分类
信息安全分析师
描述

Audit HTTP security headers for any URL and receive a grade (A+ to F) with specific recommendations for missing headers

原文语言:英语

更新
职业分类
信息安全分析师
描述

Auditoria de segurança para skills do OpenClaw. Verifica código malicioso, prompt injection, APIs perigosas e práticas inseguras. Protege contra ClawHavoc e outros ataques.

原文语言:葡萄牙语

更新
职业分类
软件开发工程师
描述

Continuous self-improvement loop — AuthorClaw learns from mistakes, successes, and user feedback to get better over time

原文语言:英语

更新
职业分类
家教
描述

Facilitator for a student doing Agents 102 Bootstrap alone — no in-person trainer. Invoke on first session to set up the working directory and orient the student; invoke subsequent sessions with "continue" to pick up where they left off. Runs as the Teacher…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Access the Semantic Scholar Graph API to search papers and retrieve paper/author/citation data when you need literature discovery or citation graph exploration.

原文语言:英语

更新
职业分类
平面设计师
描述

Use when designing or auditing icon systems, colors/badges/shapes, visual metaphors, interface signs, or naming-plus-visual surfaces that users misread. Covers semiotic reasoning across icon/index/symbol, signifier/signified, denotation/connotation/myth,…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Use when the user wants to send an SMS or WhatsApp marketing message via Twilio or Brevo, with compliance checks, consent verification, and delivery tracking.

原文语言:英语

更新
职业分类
信息安全分析师
描述

Static security analysis agent. Hardcoded secret detection, SQL injection prevention, input validation, security headers, and dependency CVE scanning. Don't use for runtime exploit verification (Probe), general code review (Judge), CI/CD management (Gear), or…

原文语言:英语

更新
职业分类
市场调研分析师与营销专员
描述

SEO, AEO (Answer Engine Optimization), and GEO strategy for search engines and AI visibility. Use when working on "SEO audit," "technical SEO," "on-page SEO," "AI search optimization," "AEO," "GEO," "AI visibility," "optimize for ChatGPT," "optimize for…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Audit content gaps and decay using Ahrefs MCP data: missing topics, thin coverage, outdated content, and decaying pages. Use this skill when planning a content roadmap, refreshing a stale catalog, building topical authority, or identifying which existing…

原文语言:英语

更新
职业分类
市场调研分析师与营销专员
描述

Plan and execute off-page SEO including link building, digital PR, brand mentions, citation building, and external authority signals. Use this skill whenever the user wants to build backlinks, plan a digital PR campaign, list local citations, run guest post…

原文语言:英语

更新
职业分类
软件开发工程师
描述

Use when designing or reviewing Server Actions: the 'use server' directive contract, how a server-side function becomes invokable from the browser without an API route, form integration via the `action` attribute, the React 19 hooks useActionState /…

原文语言:英语

更新
已展示 40 / 2,449 个已收集 Skill。