后端与 API
后端服务、API、Webhook 和服务端工具
Skills 列表

turnstile-spin
Set up Cloudflare Turnstile end-to-end in a project. Scan the codebase, create the widget via the Cloudflare API, embed it on the right forms, wire canonical server-side siteverify in the customer's existing backend, validate, and persist the skill. Load this when a user asks to add Turnstile, set up CAPTCHA, protect a form from bots, or fix a Turnstile integration. Mirrors developers.cloudflare.com/turnstile/spin.
cloudflare
cloudflare-email-service
使用 Cloudflare 邮件服务(邮件发送 + 邮件路由)发送和接收事务性邮件。适用于构建邮件发送(Workers 绑定或 REST API)、邮件路由、Agents SDK 邮件处理,或将邮件集成到任何应用(Workers、Node.js、Python、Go 等)。也适用于邮件送达率、SPF/DKIM/DMARC、wrangler 邮件设置、MCP 邮件工具,或当编码代理需要发送邮件时。即使是像“给我的 Worker 添加邮件”这样的简单请求——此技能也包含关键配置细节。
cloudflare
youtube-clipper
YouTube 视频智能剪辑工具。下载视频和字幕,AI 分析生成精细章节(几分钟级别), 用户选择片段后自动剪辑、翻译字幕为中英双语、烧录字幕到视频,并生成总结文案。 使用场景:当用户需要剪辑 YouTube 视频、生成短视频片段、制作双语字幕版本时。 关键词:视频剪辑、YouTube、字幕翻译、双语字幕、视频下载、clip video
op7418
mmx-h3-video
Generate, monitor, and download MiniMax-H3 videos through the mmx CLI. Use for H3 text-to-video, first/last-frame video, multimodal reference image/video/audio generation, H3 prompt improvement, media preflight, Pay-as-you-go API key selection, task waiting, downloads, and H3 failure handling.
minimax-ai
wp-phpstan
在WordPress项目(插件/主题/站点)中配置、运行或修复PHPStan静态分析时使用:phpstan.neon设置、基线、WordPress特定类型以及处理第三方插件类。
wordpress
cloudflare
全面的 Cloudflare 平台技能,涵盖 Workers、Pages、存储(KV、D1、R2)、AI(Workers AI、Vectorize、Agents SDK)、功能标志(Flagship)、网络(Tunnel、Spectrum)、安全(WAF、DDoS)以及基础设施即代码(Terraform、Pulumi)。适用于任何 Cloudflare 开发任务。倾向于从 Cloudflare 文档中检索,而非依赖预训练知识。
cloudflare
stripe-directory
Use when the user wants to find businesses, software, service providers, or partners for a specific industry, workflow, pain point, capability, or job to be done. Also use when the agent needs to programmatically purchase or consume a service. Use Stripe Directory to build a short relevant shortlist, even if the user does not mention Stripe Directory explicitly.
stripe
stripe-projects
当用户想要使用 Stripe Projects 配置基础设施或第三方服务时使用。触发词:"我需要一个数据库"、"设置身份验证"、"添加缓存"、"给我一个 Postgres"、"配置 Redis"、"我需要托管"、"添加向量数据库"、"给我 X 的 API 密钥"、"获取 X 的凭据"、"注册服务"、"设置监控"、"显示目录"、"我可以配置什么"、"浏览提供商"、"添加 LLM 提供商"、"配置模型提供商"、"添加邮件发送"、"设置搜索"、"添加消息队列"、"设置对象存储"、"添加功能标志"。当用户询问如何获取任何第三方服务的 API 密钥或凭据时也触发——不要让他们手动注册;先检查 Projects 目录。还用于浏览服务、检查项目状态、列出已配置的资源、查看环境变量,或任何提及 projects.dev 或添加/配置/连接云服务的情况。
stripe
domain-driven-design
使用限界上下文、聚合和通用语言围绕业务领域建模软件。当用户提到“领域建模”、“限界上下文”、“聚合根”、“通用语言”、“防腐层”、“上下文映射”、“领域事件”、“战略设计”、“代码与业务不匹配”或“如何拆分这个大系统”时使用。在将单体拆分为服务、定义服务边界或使代码结构与业务流程对齐时也触发。涵盖实体与值对象、领域事件和上下文映射策略。有关架构层,请参见clean-architecture。有关复杂性,请参见software-design-philosophy。
wondelai
upgrade-stripe
Stripe API 版本和 SDK 升级指南
stripe
nosql-injection
NoSQL injection playbook. Use when MongoDB-style operators, JSON query objects, flexible search filters, or backend query DSLs may allow data or logic abuse.
yaklang
http-parameter-pollution
HTTP Parameter Pollution (HPP): duplicate query/body keys parsed differently by servers, proxies, WAFs, and app frameworks. Use when filters and application layers disagree on which value wins, enabling bypass, SSRF second URL, logic abuse, or CSRF token confusion.
yaklang
open-redirect
Open redirect playbook. Use when URL parameters, form actions, or JavaScript sinks control navigation targets and may redirect users to attacker-controlled destinations.
yaklang
authbypass-authentication-flaws
Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.
yaklang
idor-broken-object-authorization
IDOR and broken object authorization testing playbook. Use when requests expose object identifiers, tenant boundaries, writable fields, or missing object-level authorization checks.
yaklang
ssrf-server-side-request-forgery
SSRF playbook. Use when the server fetches URLs, resolves hostnames, imports remote content, or can be driven toward internal networks, cloud metadata, or secondary protocols.
yaklang
azure-resource-visualizer
分析 Azure 资源组并生成详细的 Mermaid 架构图,展示各个资源之间的关系。适用场景:创建架构图、可视化 Azure 资源、展示资源关系、生成 Mermaid 图、分析资源组、绘制我的资源、架构可视化、资源拓扑、映射 Azure 基础设施。
microsoft
azure-aigateway
将 Azure API 管理配置为 AI 模型、MCP 工具和代理的 AI 网关。适用场景:语义缓存、令牌限制、内容安全、负载均衡、AI 模型治理、MCP 速率限制、越狱检测、添加 Azure OpenAI 后端、添加 AI Foundry 模型、测试 AI 网关、LLM 策略、配置 AI 后端、令牌指标、AI 成本控制、将 API 转换为 MCP、将 OpenAPI 导入网关。
microsoft
producthunt
搜索并检索 Product Hunt 的内容。通过 GraphQL API 获取帖子、话题、用户和合集。当用户提及 Product Hunt、PH 或产品发布时使用。
resciencelab
caveman
用于 SPEC.md 及规范相关文档的穴居人编码。由 /spec、/build、/check 加载。相比散文节省约 75% 的 token,同时保持精确。在写入 SPEC.md 或用户说出“caveman”、“compress this”、“be brief”时触发。
juliusbrussee
dockkit
Control motorized camera docks and enable intelligent subject tracking using DockKit. Use when discovering DockKit-compatible accessories, implementing camera subject tracking for faces or bodies, controlling dock motors for pan and tilt, configuring framing behavior, setting regions of interest, or building video apps with automatic camera tracking.
dpearson2699
query-address-info
Snapshot of a single wallet's token holdings on a specific chain — list of every token currently held with name, symbol, current price, 24h price change, and holding quantity. Use when the user provides an explicit wallet address (or says "my wallet") and wants the current portfolio: "what does 0x... hold", "wallet balance breakdown", "list positions for this address", "what tokens are in this wallet", "show me the holdings of <address>".
binance
trading-signal
每笔交易的聪明钱信号——每个结果都是来自追踪的聪明钱钱包的离散买入或卖出事件,包含触发价格、当前价格、触发以来的最大收益和退出率。仅支持BSC和Solana。 用于:“$X上的聪明钱买入信号”、“任何鲸鱼刚刚买入$Y”、“过去一小时的阿尔法信号”、“值得跟单的信号”、“这些交易的触发价格和最大收益”、“来自聪明钱的链上交易信号”。
binance
crypto-market-rank
加密货币市场排行榜——涵盖整个市场的排名聚合数据:社交热度/情绪排名、趋势/热搜/Binance Alpha/代币化股票排名、聪明钱净流入排名(哪些代币获得最多流入)、Pulse发射台上按突破分数排名的热门Meme代币、顶级交易员盈亏排行榜(ALL/KOL)。当用户想要按某种指标获取代币或地址的排名列表时使用——例如“热门代币”、“按热度排名前N”、“排行榜”、“按X排名”、“最大流入量”、“本周顶级交易员”。
binance