Skip to main content
在 Manus 中运行任何 Skill
一键导入
schmug
GitHub 创作者资料

schmug

按仓库查看 7 个 GitHub 仓库中的 29 个已收集 skills。

已收集 skills
29
仓库
7
更新
2026-06-02
仓库浏览

仓库与代表性 skills

当前展示该仓库 Top 8 / 9 个已收集 skills。
threat-model
信息安全分析师

Build a threat model for a target codebase and write THREAT_MODEL.md. Two modes: "bootstrap" derives a threat model from the code plus past vulnerabilities (git history, CVEs, issue tracker) with no owner present; "interview" walks an application owner through the four-question framework. Both write THREAT_MODEL.md in the shared schema (schema.md). Use when asked to "threat model", "build a threat model", "map the attack surface", or "what should we be worried about in this codebase". Read-only — never builds, runs, or fetches the target's live deployment. Adapted for dmarcheck (a TypeScript Cloudflare Worker) from anthropics/defending-code-reference-harness.

2026-05-29
vuln-scan
信息安全分析师

Static source-code vulnerability scan for the dmarcheck TypeScript Cloudflare Worker. Reads a target directory (and THREAT_MODEL.md if present), spawns parallel review subagents per focus area, and writes VULN-FINDINGS.json + .md for /vuln-triage to consume. Read-only — no building, running, or network. Category menu is tuned for web/Worker bugs (SSRF, authz/IDOR, auth bypass, injection, XSS, signature verification, secrets, redirect posture), not C/C++ memory corruption. Use when asked to "scan for vulns", "review this code for security issues", "find bugs in <dir>", or as the step between /threat-model and /vuln-triage.

2026-05-29
vuln-triage
信息安全分析师

Adversarially triage a batch of raw security-scanner findings (e.g. from /vuln-scan's VULN-FINDINGS.json). Verify each is real, collapse duplicates, re-rank by derived exploitability rather than the scanner's claimed severity, and route each to a component owner. Writes TRIAGE.json + TRIAGE.md sorted by what actually needs attention. Read-only — never executes target code or reaches the network. Named vuln-triage to avoid colliding with the repo's issue/PR /triage skill. Use when asked to "triage findings", "validate scanner output", "prioritize vulns", or "review the security backlog". Adapted for dmarcheck from anthropics/defending-code-reference-harness.

2026-05-29
dmarcus-mood-check
软件开发工程师

Invariants and conventions for DMarcus, the dmarcheck mascot (the @ creature with three legs). Use when editing src/views/components.ts, src/views/styles.ts, src/views/scripts.ts, or any view that renders the creature — to ensure sizes, moods, party-hat rules, grade-to-mood mapping, and the reduced-motion contract stay consistent.

2026-04-18
new-analyzer
软件开发工程师

Scaffold a new protocol analyzer for dmarcheck. Creates the analyzer module, types, orchestrator wiring, scoring hook-in, HTML component, and a test file — all matching the existing shape of src/analyzers/spf.ts and test/spf.test.ts. Use when adding support for a new DNS/email-security protocol (e.g. ARC, TLS-RPT, DANE).

2026-04-18
sec-patch
软件开发工程师

Generate candidate fixes for verified security findings. Consumes TRIAGE.json (preferred) or VULN-FINDINGS.json. Static-analysis input gets a per-finding patch subagent + independent reviewer and is written as inert diffs for human review. Writes PATCHES/bug_NN/{patch.diff,patch_result.json}, PATCHES.md, and PATCHES.json. Use when asked to "fix the findings", "patch these vulns", "generate fixes", or "close the loop on triage".

2026-05-28
sec-threat-model
信息安全分析师

Build a threat model for a target codebase. Three modes: "interview" walks an application owner through the four-question framework and produces a threat model from their answers; "bootstrap" derives a threat model from the code plus past vulnerabilities (CVEs, git history, pentest reports) when no owner is available; "bootstrap-then-interview" chains the two when both owner and codebase are present. All write THREAT_MODEL.md in a shared schema. Use when asked to "threat model", "build a threat model", "map the attack surface", or "what should we be worried about in this codebase".

2026-05-28
sec-triage
信息安全分析师

Triage a batch of raw security findings. Verify each is real, collapse duplicates, re-rank by derived exploitability, and tag with an owner. Takes a directory or file of scanner output and writes TRIAGE.json + TRIAGE.md sorted by what actually needs engineering attention. Use when asked to "triage findings", "validate scanner output", "prioritize vulns", or "review the backlog". Runs interactively by default; pass --auto to skip the interview.

2026-05-28
sec-vuln-scan
信息安全分析师

Static source-code vulnerability scan. Reads a target directory (and THREAT_MODEL.md if present), spawns parallel review subagents per focus area, and writes VULN-FINDINGS.json + .md for /sec-triage to consume. Read-only — no building, running, or network. Use when asked to "scan for vulns", "review this code for security issues", "find bugs in <dir>", or as the step between /sec-threat-model and /sec-triage.

2026-05-28
已展示 7 / 7 个仓库
已展示全部仓库