Skip to main content
在 Manus 中运行任何 Skill
一键导入
GitHub 仓库

ai-ide-skills

ai-ide-skills 收录了来自 Mindgard 的 8 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。

已收集 skills
8
Stars
61
更新
2026-03-09
Forks
8
职业覆盖
1 个职业分类 · 已分类 100%
仓库浏览

这个仓库中的 skills

ai-ide-attack-chains
信息安全分析师

Plans and constructs multi-stage attack chains against AI IDEs. Use when combining vulnerability primitives into end-to-end exploits, assessing overall IDE security posture, or mapping how individual vulnerabilities chain together through the file-write pivot point. Each chain is classified by interaction tier to prioritize reportable findings.

2026-03-09
ai-ide-code-exec
信息安全分析师

Tests AI IDEs for code execution vulnerabilities beyond MCP and terminal filters. Use when assessing hooks abuse, binary planting, IDE settings exploitation, tools definition auto-loading, or environment variable prefixing attack vectors. Patterns are ordered by interaction tier: Tier 1 (zero-interaction) through Tier 4 (trusted workspace + specific action).

2026-03-09
ai-ide-data-exfil
信息安全分析师

Tests AI IDEs for data exfiltration vulnerabilities. Use when assessing markdown image rendering, Mermaid diagram abuse, pre-configured URL fetching, model provider redirect, webview rendering, or other outbound data channels in AI coding assistants.

2026-03-09
mcp-config-poisoning
信息安全分析师

Tests AI IDEs for MCP configuration poisoning vulnerabilities. Use when auditing MCP integration security, testing whether an IDE auto-loads untrusted MCP server definitions from workspace config files, or assessing MCP tool approval and invocation controls. Assessment is structured around four interaction tiers, tested in priority order from zero-click auto-load to TOCTOU on trusted workspaces.

2026-03-09
ai-ide-recon
信息安全分析师

Maps attack surface of AI-assisted IDEs before vulnerability testing. Use when starting a security assessment of an AI IDE, analyzing IDE documentation for security blind spots, or enumerating config files and auto-load paths. Works for both open-source and closed-source targets. Annotates every discovered feature with an interaction tier so testing prioritizes zero-click and agent-mediated vectors first.

2026-03-03
ai-ide-source-audit
信息安全分析师

Guides source code auditing of open-source AI IDEs for security vulnerabilities. Use when reviewing AI IDE source code, analyzing command filtering implementations, auditing MCP integration code, or assessing file-write permission models in open-source AI coding tools.

2026-03-03
prompt-injection-chains
信息安全分析师

Tests AI IDEs for prompt injection vulnerabilities that enable config modification and privilege escalation. Use when assessing adversarial directory attacks, prompt template auto-loading, rules override, or file-write-to-config-modification attack chains. Patterns are organized by interaction tier from highest to lowest severity.

2026-03-03
terminal-filter-bypass
信息安全分析师

Tests terminal command filtering and allowlist implementations in AI IDEs for bypass vulnerabilities. Use when assessing command execution controls, testing shell injection vectors, or evaluating allowlist/blocklist implementations in AI coding agents.

2026-03-03