Skip to main content
在 Manus 中运行任何 Skill
一键导入
RedHatProductSecurity
GitHub 创作者资料

RedHatProductSecurity

按仓库查看 2 个 GitHub 仓库中的 154 个已收集 skills。

已收集 skills
154
仓库
2
更新
2026-07-15
仓库浏览

仓库与代表性 skills

ai-code-review
软件质量保证分析师与测试员

Security-focused review of AI-generated or AI-assisted code. Use when reviewing code produced by AI coding assistants, auditing AI-generated patches, verifying AI-assisted contributions before merge, or when a review needs to account for failure modes specific to AI code generation.

2026-07-15
network-security
信息安全分析师

Configure Kubernetes network security including host access restrictions, network policies, port management, and connectivity requirements. Use when writing, reviewing, or auditing pod specs, Services, NetworkPolicies, or NetworkAttachmentDefinitions.

2026-07-15
ai-systems-security
信息安全分析师

Secure AI-powered products and infrastructure. Use when integrating LLM APIs, deploying model-serving infrastructure, building agent workflows, connecting MCP servers, or reviewing AI system architecture for security gaps.

2026-07-15
authentication
信息安全分析师

Enforce standard authentication for external data source connections. Use when integrating, configuring, or reviewing connections from AI systems to external databases, APIs, or data services.

2026-07-15
container-hardening
网络与计算机系统管理员

Harden container images and runtime configuration. Use when building, reviewing, or auditing Containerfiles, Dockerfiles, container compose files, or Kubernetes pod security settings.

2026-07-15
dependency-vulnerability-audit
软件质量保证分析师与测试员

Supply chain security audit using CLI vulnerability scanners, license compliance checks, and supply chain risk assessment. Use when auditing project dependencies for known CVEs, license concerns, and supply chain health.

2026-07-15
input-validation-injection
软件开发工程师

Apply when reviewing or writing code that processes untrusted input, constructs queries or commands, or handles user-supplied data. Covers SQL, LDAP, OS command injection, prototype pollution, and general validation strategy.

2026-07-15
logging
信息安全分析师

Enforce logging of access to sensitive external data sources in AI systems. Use when designing, building, or reviewing audit and logging capabilities for AI systems accessing external databases or data services.

2026-07-15
当前展示该仓库 Top 8 / 145 个已收集 skills。
secdevai-tool
信息安全分析师

Run external security analysis tools (Bandit, Gosec, Scorecard, Semgrep) inside read-only containers via podman/docker. Use when the user wants to execute specific security tools, combine their output with AI analysis, or run all available tools at once.

2026-04-23
secdevai-review
信息安全分析师

Perform AI-powered security code review using OWASP Top 10, CWE/SANS Top 25, and WSTG patterns. Use when reviewing source code, specific files, git commits, or entire codebases for security vulnerabilities. Supports web and non-web code (C/C++, Go, Rust, etc.), multi-language analysis, severity classification, and automated finding validation via subagent.

2026-04-22
secdevai
信息安全分析师

AI-powered secure development assistant. Dispatches to review, fix, tool, and export subcommands. Use when the user invokes /secdevai with no subcommand or needs an overview of available security commands.

2026-04-22
secdevai-validate
信息安全分析师

Validate security findings for exploitability, severity accuracy, and CVSS scoring. Use when secdevai-review dispatches findings for validation, or when the user invokes /secdevai validate to re-validate prior results. Rejects false positives, calibrates severity to Red Hat classification, and produces per-finding CVSS v3.1 analysis.

2026-04-22
secdevai-dast
信息安全分析师

Dynamic Application Security Testing (DAST) using RapiDAST and ZAP. Use when the user wants to scan a running web app or API for security vulnerabilities, run a DAST scan, test a service endpoint, use RapiDAST or ZAP, or says "/secdevai dast" or "/secdevai-dast". Auto-detects Dockerfile/Compose for containerized targets, finds OpenAPI specs, guides the full scan workflow from target setup through SARIF result export, and — uniquely — traces each DAST finding back to the exact source file and line that is the root cause.

2026-04-22
secdevai-export
信息安全分析师

Export security review results to Markdown and SARIF report formats. Use when the user wants to save, export, or generate reports from security review findings produced by /secdevai review, /secdevai fix, or /secdevai tool.

2026-04-22
secdevai-help
信息安全分析师

Display all available SecDevAI commands, usage examples, aliases, and configuration options. Use when the user asks for help, needs a command reference, or wants to see the typical security review workflow.

2026-04-20
secdevai-oci-image-security
信息安全分析师

Analyze OCI container images for security vulnerabilities, misconfigurations, supply chain risks, and hardening gaps. Use when reviewing container images from Red Hat, Quay.io, Docker Hub, or any OCI-compliant registry. Covers CVE analysis, config security, EOL component detection, credential exposure, and TLS/crypto misconfigurations.

2026-03-10
当前展示该仓库 Top 8 / 9 个已收集 skills。
已展示 2 / 2 个仓库
已展示全部仓库