安全

安全审查、认证、权限和风险检查

599 个 Skills 可用

Skills 列表

security-scan

security-scan

707security

Deep security scanning for .NET applications across 6 layers: vulnerable packages, secrets detection, OWASP code patterns, auth configuration, CORS policy, and data protection. Produces severity-rated findings with specific remediation steps. Load this skill when: "security scan", "security audit", "check for vulnerabilities", "find secrets", "OWASP", "auth review", "CORS check", "security review", "penetration test prep", "CVE check", "vulnerability scan", "hardcoded password", "data protection", "security posture".

codewithmukesh avatarcodewithmukesh
获取
authentication

authentication

707security

Authentication and authorization for ASP.NET Core. Covers JWT bearer tokens, OpenID Connect, ASP.NET Identity, authorization policies, role and claim-based authorization, and API key authentication. Load this skill when implementing login, protecting endpoints, designing authorization rules, or when the user mentions "auth", "JWT", "bearer token", "OIDC", "OpenID Connect", "Identity", "claims", "roles", "authorize", "RequireAuthorization", "API key", or "cookie auth".

codewithmukesh avatarcodewithmukesh
获取
scalar

scalar

707security

Scalar API documentation UI for .NET 10 applications. Covers setup, themes, authentication prefill, multiple documents, layout options, and security. A modern replacement for Swagger UI. Load this skill when setting up API documentation UI, or when the user mentions "Scalar", "MapScalarApiReference", "API reference", "Swagger UI replacement", "API documentation UI", "Scalar theme", "interactive API docs", or "Try It".

codewithmukesh avatarcodewithmukesh
获取
nuxt-studio

nuxt-studio

706security

Configure and operate the self-hosted Nuxt Studio editor for Nuxt Content. Use when working with nuxt-studio installation, editor customization, OAuth or custom authentication, media, drafts, Git publishing, or production deployment.

onmax avataronmax
获取
android-kotlin

android-kotlin

705testing-qa

Android Kotlin development with Coroutines, Jetpack Compose, Hilt, and MockK testing

alinaqi avataralinaqi
获取
pwa-development

pwa-development

705frontend

Progressive Web Apps - service workers, caching strategies, offline, Workbox

alinaqi avataralinaqi
获取
playwright-testing

playwright-testing

705testing-qa

E2E testing with Playwright - Page Objects, cross-browser, CI/CD

alinaqi avataralinaqi
获取
code-review

code-review

705testing-qa

Mandatory code reviews via /code-review before commits and deploys

alinaqi avataralinaqi
获取
ui-mobile

ui-mobile

705design-ui

Mobile UI patterns - React Native, iOS/Android, touch targets

alinaqi avataralinaqi
获取
pwa-development

pwa-development

704frontend

渐进式Web应用 - Service Worker、缓存策略、离线支持、Workbox

alinaqi avataralinaqi
获取
playwright-testing

playwright-testing

704testing-qa

使用 Playwright 进行端到端测试 - 页面对象、跨浏览器、CI/CD

alinaqi avataralinaqi
获取
android-kotlin

android-kotlin

703testing-qa

Android Kotlin development with Coroutines, Jetpack Compose, Hilt, and MockK testing

alinaqi avataralinaqi
获取
setup-vivox-voice-chat

setup-vivox-voice-chat

680security

Add and configure in-game voice chat and text chat for Unity multiplayer games using Unity Vivox. Covers microphone setup and mic permissions on Android/iOS, voice activity detection (VAD) tuning, voice volume and mute controls in a settings UI (VoiceVadMinimumVolume, mic slider, mute button, speaking indicator), proximity/3D spatial voice for FPS/co-op games, team/party/lobby/guild voice channels, push-to-talk, muting self and other players, whisper/direct messages, in-game text chat, and Vivox SDK init + Unity Authentication sign-in. Use when the user asks to add voice chat, voice comms, microphone/mic support, a voice-chat settings UI, mute button, VAD threshold, push-to-talk, proximity or spatial voice, team voice, party chat, lobby chat, direct messages, or mentions Vivox, VivoxService, com.unity.services.vivox, JoinGroupChannelAsync, JoinPositionalChannelAsync, LoginAsync, or migrating from legacy Vivox (Client.Instance / LoginSession / AccountId).

unity-technologies avatarunity-technologies
获取
angular-routing

angular-routing

596security

在 Angular v20+ 应用中实现路由,支持懒加载、函数式守卫、解析器和路由参数。用于导航设置、受保护路由、基于路由的数据加载和嵌套路由。触发条件包括路由配置、添加认证守卫、实现懒加载或使用信号读取路由参数。

analogjs avataranalogjs
获取
angular-http

angular-http

596security

使用 Angular v20+ 中的 resource()、httpResource() 和 HttpClient 实现 HTTP 数据获取。适用于 API 调用、基于信号的 data loading、请求/响应处理以及拦截器。触发场景包括数据获取、API 集成、加载状态、错误处理,或将基于 Observable 的 HTTP 模式转换为基于信号的模式。

analogjs avataranalogjs
获取
kibana-connectors

kibana-connectors

546security

Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform. Use when configuring third-party integrations or managing connectors as code.

elastic avatarelastic
获取
elasticsearch-security-troubleshooting

elasticsearch-security-troubleshooting

546security

Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues. Use when the user reports a security error.

elastic avatarelastic
获取
kibana-audit

kibana-audit

546security

Enable and configure Kibana audit logging for saved object access, logins, and space operations. Use when setting up Kibana audit, filtering events, or correlating Kibana and ES audit logs.

elastic avatarelastic
获取
elasticsearch-audit

elasticsearch-audit

545security

Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.

elastic avatarelastic
获取
elasticsearch-authz

elasticsearch-authz

545security

Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP/SAML.

elastic avatarelastic
获取
tts

tts

519security

当用户需要将文本转换为语音、从文本生成音频或制作配音时使用此技能。触发条件包括:任何提及“TTS”、“文本转语音”、“朗读”、“说出”、“语音”、“读出来”、“音频旁白”、“配音”、“译制”,或要求将书面内容转为口语音频的请求。也适用于将EPUB/PDF/SRT/文章转换为音频、从参考音频克隆声音、控制语音中的情感或语速、将语音对齐到字幕时间线,或生成每段语音映射的音频。

noizai avatarnoizai
获取
n8n-subworkflows-official

n8n-subworkflows-official

481security

Use when building anything multi-step, anything that looks repeatable, anything the user mentions reusing, or any workflow with more than ~10 nodes. Triggers on "reuse", "I do this in another workflow", "extract", "modular", "shared logic", "subworkflow", multi-step builds, or any task that mentions logic the user has built before.

n8n-io avatarn8n-io
获取
n8n-credentials-and-security-official

n8n-credentials-and-security-official

478security

Use when handling any auth, API keys, tokens, OAuth, bearer tokens, basic auth, or secret values in n8n workflows. Triggers on "API key", "token", "bearer", "OAuth", "secret", "auth", "credentials", "Authorization header", "x-api-key", or any node configuration that mentions a third-party service.

n8n-io avatarn8n-io
获取
ai-research-explore

ai-research-explore

449security

与Rigor Explore兼容的技能标识,用于有意义且可能具有新颖性的深度学习研究候选方案。当研究者已选择任务族、数据集、基准、评估方法,提供SOTA参考,并希望在`current_research`基础上进行仅候选方案的探索,且要求可审计的仓库理解、想法筛选、公平比较以及将受控实验写入`explore_outputs/`时使用。不适用于以README为先的可信复现、开放式方向探索、狭窄的仅代码或仅运行探索、被动仓库分析、已验证的新颖性声明或隐式实验。

lllllllama avatarlllllllama
获取