安全

安全审查、认证、权限和风险检查

599 个 Skills 可用

Skills 列表

authentication

authentication

932security

Implement iOS authentication flows with AuthenticationServices and LocalAuthentication. Use when building Sign in with Apple, passkey/WebAuthn registration or sign-in with ASAuthorizationPlatformPublicKeyCredentialProvider, ASAuthorizationController credential state and revocation handling, ASWebAuthenticationSession OAuth or third-party login, Password AutoFill, identity-token server validation, or local biometric re-authentication with LAContext.

dpearson2699 avatardpearson2699
获取
push-notifications

push-notifications

931security

在 iOS/macOS 应用中实现、审查或调试推送通知——本地通知、远程(APNs)通知、富通知、通知操作、静默推送以及通知服务/内容扩展。适用于使用 UNUserNotificationCenter、注册远程通知、处理通知负载、设置通知类别和操作、创建富通知内容或调试通知投递。也适用于在 Swift 应用中处理提醒、角标、声音、后台推送或用户通知权限。

dpearson2699 avatardpearson2699
获取
ios-networking

ios-networking

927security

使用 async/await 和结构化并发,在 iOS/macOS 应用中构建、审查或改进基于 URLSession 的网络代码。适用于 REST API、文件下载、数据上传、WebSocket 连接、分页、重试逻辑、请求中间件、缓存、后台传输或网络可达性监控。也适用于处理 Swift 应用中的 HTTP 请求、API 客户端、网络错误处理或数据获取。

dpearson2699 avatardpearson2699
获取
platform-architecture-analyze

platform-architecture-analyze

920security

Analyze a Salesforce project against the Salesforce Well-Architected framework (Trusted / Easy / Adaptable). Use when the developer asks to \"review the architecture\", \"run a Well-Architected check\", \"audit this project\", \"is this project well-architected?\", \"assess security/governor-limit/packageability risk across the project\", or wants a holistic code-and-metadata health report. Grades the criteria that are observable from code and metadata (sharing/FLS, bulkification, selective SOQL, trigger-handler separation, legacy tech, packageability) with file:line evidence, and emits a human checklist for governance/process pillars it cannot see (security matrix, BCP, roadmaps, AI governance). Distinct from `dx-code-analyzer-run` (single-tool Code Analyzer scan of Apex) — this skill is a multi-pillar architectural review that orchestrates several analysis skills and maps findings to Well-Architected. Read-only: it grades and advises, never edits.

forcedotcom avatarforcedotcom
获取
vibe-security

vibe-security

904security

审计代码库中 AI 编码助手在“氛围编码”应用中引入的常见安全漏洞。检查暴露的 API 密钥、失效的访问控制(Supabase RLS、Firebase 规则)、缺失的身份验证验证、客户端信任问题、不安全的支付流程等。当用户询问安全问题、想要代码审查、提到“氛围编码”,或者当您编写或审查涉及身份验证、支付、数据库访问、API 密钥、机密或用户数据的代码时,请使用此技能——即使他们未明确提及安全。当用户说“这安全吗?”、“检查我的代码”、“审计这个”、“审查漏洞”或“有人能黑这个吗?”时,也触发此技能。

raroque avatarraroque
获取
skill-scanner

skill-scanner

896security

Scan agent skills for security issues. Use when asked to "scan a skill",

getsentry avatargetsentry
获取
sales-agentforce-pipeline-management-configure

sales-agentforce-pipeline-management-configure

892security

Use to configure, set up, or repair the Sales Management agent and Agentforce Pipeline Management in a Salesforce org. Automates metadata creation for flows, prompt templates, permission sets, and data source configuration. TRIGGER when: user wants to enable Pipeline Management, configure Sales pipeline features, set up the Sales Management agent for opportunity field updates (including autonomous updates), connect enabled data sources like Einstein Conversation Insights or Einstein Activity Capture, customize opportunity stage descriptions, configure post-meeting suggestions, verify or audit configuration status, fix partially configured orgs, or troubleshoot Pipeline Management metadata issues. DO NOT TRIGGER when: user wants to build a custom agent (use agentforce-generate), configure general Agentforce tracing (use platform-tracing-agentforce-configure), work with non-Sales agents, or enable Einstein Conversation Insights or Einstein Activity Capture from scratch (provisioning is out of scope).

forcedotcom avatarforcedotcom
获取
gha-security-review

gha-security-review

883security

对GitHub Actions工作流进行安全审查,发现可利用的漏洞。当被要求“审查GitHub Actions”、“审计工作流”、“检查CI安全”、“GHA安全”、“工作流安全审查”,或审查.github/workflows/中的pwn请求、表达式注入、凭证窃取和供应链攻击时使用。专注于利用,提供具体的PoC场景。

getsentry avatargetsentry
获取
find-bugs

find-bugs

867security

查找本地分支变更中的错误、安全漏洞和代码质量问题。当被要求审查变更、查找错误、进行安全审查或审计当前分支上的代码时使用。

getsentry avatargetsentry
获取
security-review

security-review

850security

安全代码审查,用于发现漏洞。当被要求进行“安全审查”、“查找漏洞”、“检查安全问题”、“审计安全”、“OWASP审查”或审查代码中的注入、XSS、认证、授权、加密问题时使用。提供基于置信度的系统性审查报告。

getsentry avatargetsentry
获取
platform-sharing-owd-configure

platform-sharing-owd-configure

848security

Use when the user wants to retrieve or update Organization-Wide Default (OWD) sharing settings for Salesforce objects. TRIGGER when: user asks to check current OWD settings, view sharing defaults, change default access levels (Private, Public Read Only, Public Read/Write, Controlled by Parent), configure internal or external access for standard or custom objects, mentions org-wide defaults, wants to make records private or restrict who can see records, wants to control default record visibility for an object, or references .settings-meta.xml sharing fields or sharingModel in .object-meta.xml files. DO NOT TRIGGER when: user asks about sharing rules, criteria-based sharing, role hierarchy, or manual sharing — delegate to platform-sharing-rules-generate.

forcedotcom avatarforcedotcom
获取
dx-pkg-post-install-configure

dx-pkg-post-install-configure

832security

Use this skill to automate managed package post-install configuration. Package-agnostic — works with any managed package (LMA, FMA, work.com, Certinia, etc.). TRIGGER when: user installs a managed package and needs post-install configuration, mentions LMA/FMA/work.com post-install setup, asks to configure permission sets/FLS/page layouts for an installed package, says 'post-install', 'package setup', 'configure LMA', 'set up FMA', 'post-install steps'. DO NOT TRIGGER for: standalone permission set assignment (use dx-org-permission-set-assign), generating permission set metadata XML (use platform-permission-set-generate), package installation, or org switching.

forcedotcom avatarforcedotcom
获取
platform-policy-rule-generate

platform-policy-rule-generate

827security

Use this skill when authoring PolicyRuleDefinition and PolicyRuleDefinitionSet metadata XML for Salesforce Data Cloud governance policies, or when editing *.policyRuleDefinition / *.policyRuleDefinitionSet files. Covers the category decision tree, full schema for all policy variants (ACCESS, GOVERNANCE, RECORD, TRANSFORM), UI-compatibility rules for the Data Governance Policy Builder, output hygiene for user-facing agent responses, and validation guardrails. Do NOT use this skill for UserAccessPolicy, AccessPolicy, SharingRules, PermissionSet, or any other access-control metadata type — those have their own types and live outside the PolicyRuleDefinition schema.

forcedotcom avatarforcedotcom
获取
building-omnistudio-callable-apex

building-omnistudio-callable-apex

801security

Salesforce Industries Common Core (OmniStudio/Vlocity) Apex callable generation and review skill with 120-point scoring. Use when creating, reviewing, or migrating Industries callable Apex implementations. TRIGGER when: user creates or reviews System.Callable classes, migrates VlocityOpenInterface or VlocityOpenInterface2, or builds Industries callable extensions used by OmniStudio, Integration Procedures, or DataRaptors. DO NOT TRIGGER when: generic Apex classes or triggers (use generating-apex), building Integration Procedures (use building-omnistudio-integration-procedure), authoring OmniScripts (use building-omnistudio-omniscript), configuring Data Mappers (use building-omnistudio-datamapper), or analyzing namespace/dependency issues (use analyzing-omnistudio-dependencies).

forcedotcom avatarforcedotcom
获取
integration-connectivity-connected-app-configure

integration-connectivity-connected-app-configure

783security

Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring. Use this skill to configure OAuth flows, JWT bearer auth, Connected Apps, and External Client Apps in Salesforce. TRIGGER when: user configures OAuth flows, JWT bearer auth, Connected Apps, ECAs, or touches .connectedApp-meta.xml / .eca-meta.xml files. DO NOT TRIGGER when: configuring Named Credentials for callouts (use integration-connectivity-generate), reviewing permission policies (use platform-metadata-deploy), or writing Apex token-handling code (use platform-apex-generate).

forcedotcom avatarforcedotcom
获取
experience-ui-bundle-deploy

experience-ui-bundle-deploy

783security

MUST activate when the project contains a uiBundles/*/src/ directory and the task involves deploying, pushing to an org, or post-deploy org setup. Use this skill to deploy a UI bundle app to a Salesforce org and run the full ordered setup: org authentication, pre-deploy build, metadata deploy, permission-set assignment, role assignment, Experience Cloud self-registration, seed-data import, and GraphQL schema fetch plus codegen. Activate when a uiBundles/ project also has files like *.network-meta.xml, org-setup.config.json, a data-plan.json in the data/ dir, or sfdx-project.json and the user mentions deploying, pushing, org setup, or post-deploy tasks. DO NOT TRIGGER when: creating a new UI bundle project from scratch (use experience-ui-bundle-project-generate); styling or editing pages in an existing app without deploying (use experience-ui-bundle-frontend-generate); adding a specific feature such as auth, search, or file upload without deploying (use the matching experience-ui-bundle-*-generate skill).

forcedotcom avatarforcedotcom
获取
platform-agentsetup-categories-fetch

platform-agentsetup-categories-fetch

783security

Fetch agentic setup prompt categories from a connected Salesforce org using the Connect API. Use this skill to call GET /agenticsetup/categories and return the list of prompt categories, optionally with their nested prompts. TRIGGER when: user asks to get, fetch, list, or show agentic setup categories, prompt categories, setup copilot categories, prompt library categories, available setup prompts, Agentforce prompt library, or copilot prompts. DO NOT TRIGGER when: user wants to create new categories, work with non-categories endpoints, or generate OpenAPI specs.

forcedotcom avatarforcedotcom
获取
dx-org-permission-set-assign

dx-org-permission-set-assign

780security

ALWAYS USE THIS SKILL to assign permission sets to org users. Assign one or more permission sets to org users using the sf org assign permset command. TRIGGER when the user asks to assign, grant, give, add, or apply permission sets to users, admins, specific orgs, or specific users. Supports granting permissions, giving access, and adding permission sets to default admin or specific users via --on-behalf-of. DO NOT TRIGGER for listing permission sets or checking user permissions.

forcedotcom avatarforcedotcom
获取
platform-sharing-rules-generate

platform-sharing-rules-generate

774security

当用户需要创建、编辑、删除或管理 Salesforce 共享规则元数据时,使用此技能。触发条件:用户提及共享规则、记录共享、基于条件的共享、基于角色的共享、访客用户共享、sharingRules、sharingCriteriaRules、sharingGuestRules、sharingOwnerRules、.sharingRules-meta.xml 文件,或要求与特定角色或组共享记录。当用户想要修改或删除现有共享规则,或更新共享规则条件或访问级别时,也触发。当用户需要权限集或配置文件(使用 platform-permission-set-generate),或需要对象级安全而非记录级共享(使用 platform-permission-set-generate)时,不要触发。

forcedotcom avatarforcedotcom
获取
link-cli

link-cli

771security

Install and authenticate Link CLI for agent payments, financial insights, or both. Use when a user is setting up Link CLI for the first time, asks to connect or log in to Link, or needs to configure Link access before using payment or financial-data features.

stripe avatarstripe
获取
verified-agent-identity

verified-agent-identity

753security

了解你的智能体(KYA)。基于Billions网络的去中心化身份系统,用于智能体。通过Billions ERC-8004和认证注册表将智能体与人类身份关联。验证并生成认证证明。基于iden3自主身份协议。

billionsnetwork avatarbillionsnetwork
获取
azure-sql-database

azure-sql-database

745security

Expert knowledge for Azure SQL Database development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when choosing DTU/vCore tiers, configuring Hyperscale/HA, setting geo-replication/Data Sync, or automating CI/CD, and other Azure SQL Database related development tasks. Not for Azure SQL Managed Instance (use azure-sql-managed-instance), SQL Server on Azure Virtual Machines (use azure-sql-virtual-machines), Azure Cosmos DB (use azure-cosmos-db), Azure Data Factory (use azure-data-factory).

microsoftdocs avatarmicrosoftdocs
获取
financial-insights

financial-insights

718security

Reads a user's Link financial data — transactions, balances, and wallet sources — so agents can answer questions about spending and available source capabilities. Use when the user says "check my balance", "how much did I spend", "show my transactions", "what accounts are connected", "summarize my spending", "recent purchases", or asks about their financial activity, account balances, or linked sources.

stripe avatarstripe
获取
outdated

outdated

710security

Dependency health report for .NET solutions: outdated NuGet packages, vulnerable versions, and commercial-license traps (MediatR, MassTransit, FluentAssertions, AutoMapper) — powered by the get_nuget_packages MCP tool. Invoke when: "outdated packages", "check dependencies", "stale packages", "package audit", "dependency health", "are my packages up to date", "license check", "vulnerable packages", "nuget audit".

codewithmukesh avatarcodewithmukesh
获取