Skip to main content
在 Manus 中运行任何 Skill
一键导入
Mindgard
GitHub 创作者资料

Mindgard

按仓库查看 1 个 GitHub 仓库中的 8 个已收集 skills。

已收集 skills
8
仓库
1
更新
2026-03-09
仓库分布

Skills 分布在哪些仓库

按已收集 skill 数展示主要仓库,并显示它们在该创作者目录中的占比和职业覆盖。

仓库浏览

仓库与代表性 skills

ai-ide-attack-chains
信息安全分析师

Plans and constructs multi-stage attack chains against AI IDEs. Use when combining vulnerability primitives into end-to-end exploits, assessing overall IDE security posture, or mapping how individual vulnerabilities chain together through the file-write pivot point. Each chain is classified by interaction tier to prioritize reportable findings.

2026-03-09
ai-ide-code-exec
信息安全分析师

Tests AI IDEs for code execution vulnerabilities beyond MCP and terminal filters. Use when assessing hooks abuse, binary planting, IDE settings exploitation, tools definition auto-loading, or environment variable prefixing attack vectors. Patterns are ordered by interaction tier: Tier 1 (zero-interaction) through Tier 4 (trusted workspace + specific action).

2026-03-09
ai-ide-data-exfil
信息安全分析师

Tests AI IDEs for data exfiltration vulnerabilities. Use when assessing markdown image rendering, Mermaid diagram abuse, pre-configured URL fetching, model provider redirect, webview rendering, or other outbound data channels in AI coding assistants.

2026-03-09
mcp-config-poisoning
信息安全分析师

Tests AI IDEs for MCP configuration poisoning vulnerabilities. Use when auditing MCP integration security, testing whether an IDE auto-loads untrusted MCP server definitions from workspace config files, or assessing MCP tool approval and invocation controls. Assessment is structured around four interaction tiers, tested in priority order from zero-click auto-load to TOCTOU on trusted workspaces.

2026-03-09
ai-ide-recon
信息安全分析师

Maps attack surface of AI-assisted IDEs before vulnerability testing. Use when starting a security assessment of an AI IDE, analyzing IDE documentation for security blind spots, or enumerating config files and auto-load paths. Works for both open-source and closed-source targets. Annotates every discovered feature with an interaction tier so testing prioritizes zero-click and agent-mediated vectors first.

2026-03-03
ai-ide-source-audit
信息安全分析师

Guides source code auditing of open-source AI IDEs for security vulnerabilities. Use when reviewing AI IDE source code, analyzing command filtering implementations, auditing MCP integration code, or assessing file-write permission models in open-source AI coding tools.

2026-03-03
prompt-injection-chains
信息安全分析师

Tests AI IDEs for prompt injection vulnerabilities that enable config modification and privilege escalation. Use when assessing adversarial directory attacks, prompt template auto-loading, rules override, or file-write-to-config-modification attack chains. Patterns are organized by interaction tier from highest to lowest severity.

2026-03-03
terminal-filter-bypass
信息安全分析师

Tests terminal command filtering and allowlist implementations in AI IDEs for bypass vulnerabilities. Use when assessing command execution controls, testing shell injection vectors, or evaluating allowlist/blocklist implementations in AI coding agents.

2026-03-03
已展示 1 / 1 个仓库
已展示全部仓库