Skip to main content
GitHub 仓库

scira

scira 收录了来自 makash 的 2 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。

已收集 skills
2
Stars
2
更新
2026-03-31
Forks
0
职业覆盖
1 个职业分类 · 已分类 100%
仓库浏览

这个仓库中的 skills

npm-supply-chain-response
信息安全分析师

Respond to npm supply chain attacks and compromised package incidents. Use this skill whenever a user mentions a compromised npm package, an npm supply chain attack, a malicious dependency in node_modules, credential-stealing malware from npm install, or asks how to check if they're affected by a package compromise on npm. Also trigger when the user asks about postinstall script backdoors, typosquatted npm packages, hunting for IOCs after an npm install, auditing node environments for malicious packages, or generating an incident response checklist for an npm compromise. Trigger even if the user just names a package and says it was "hacked", "backdoored", "compromised", or "pwned" and the package is from npm, yarn, or pnpm. Covers axios, plain-crypto-js, and any future npm supply chain incident.

2026-03-31
pypi-supply-chain-response
信息安全分析师

Respond to Python/PyPI supply chain attacks and compromised package incidents. Use this skill whenever a user mentions a compromised Python package, a PyPI supply chain attack, a malicious dependency, credential-stealing malware in a pip package, or asks how to check if they're affected by a package compromise. Also trigger when the user asks about rotating credentials after a Python package incident, finding transitive dependencies, hunting for IOCs from a pip install, auditing Python environments for malicious packages, or generating an incident response checklist for a PyPI compromise. Trigger even if the user just names a package and says it was "hacked", "backdoored", "compromised", or "pwned".

2026-03-26