安全
安全审查、认证、权限和风险检查
Skills 列表

elicit
Run a structured discovery session to build an Allium specification through conversation. Use when the user wants to create a new spec from scratch, elicit or gather requirements, capture domain behaviour, specify a feature or system, define what a system should do, or is describing functionality and needs help shaping it into a specification.
juxt
firestore-rules-creation
Designs, authors, refactors, and hardens production-grade Cloud Firestore Security Rules (firestore.rules). Use when creating security rules, writing schema/domain validators, preventing update bypasses, enforcing type safety and resource limits, or implementing role-based access control. Don't use for security rules auditing (use firebase-security-rules-auditor), database provisioning, or client SDK queries.
firebase
avatar-video
Create AI avatar videos with precise control over avatars, voices, scripts, and backgrounds using HeyGen's v3 API (POST /v3/videos). Two modes: type=\"avatar\" with avatar_id, or type=\"image\" with an image AssetInput (Avatar IV). Use when: (1) Choosing a specific avatar and voice for a video, (2) Writing exact scripts for an avatar to speak, (3) Animating a photo into a speaking video (type=\"image\"), (4) Transparent background videos with remove_background, (5) Integrating HeyGen avatars with Remotion, (6) Batch video generation with exact specs, (7) Brand-consistent production videos with precise control.
heygen-com
sf-connected-apps
Salesforce Connected Apps and OAuth configuration with 120-point scoring. TRIGGER when: user configures OAuth flows, JWT bearer auth, Connected Apps, or touches .connectedApp-meta.xml / .eca-meta.xml files. DO NOT TRIGGER when: Named Credentials for callouts (use sf-integration), permission policies (use sf-permissions), or API endpoint code (use sf-apex).
jaganpro
sf-diagram-mermaid
Salesforce architecture diagrams using Mermaid with ASCII fallback. TRIGGER when: user says "diagram", "visualize", "ERD", or asks for sequence diagrams, flowcharts, class diagrams, or architecture visualizations in Mermaid. DO NOT TRIGGER when: user wants PNG/SVG image output (use sf-diagram-nanobananapro), or asks about non-Salesforce systems.
jaganpro
skill-creator
Create or update a Codex skill with appropriately scoped instructions and any needed supporting resources.
aiskillstore
sf-permissions
Permission Set analysis, hierarchy viewer, and access auditing. TRIGGER when: user asks "who has access to X?", analyzes permission sets/groups, or touches .permissionset-meta.xml / .permissionsetgroup-meta.xml files. DO NOT TRIGGER when: creating new metadata (use sf-metadata), deploying permission sets (use sf-deploy), or Apex sharing logic (use sf-apex).
jaganpro
speech-engine
Add real-time voice conversations to a custom agent runtime with ElevenLabs Speech Engine. Use when building Speech Engine servers, WebSocket handlers, WebRTC browser clients, conversation token endpoints, interruption-aware streaming responses, or voice-enabled chat agents that connect developer-owned server logic to ElevenLabs speech-to-text and text-to-speech.
elevenlabs
convex-security-audit
Deep security review patterns for authorization logic, data access boundaries, action isolation, rate limiting, and protecting sensitive operations
waynesutton
convex-http-actions
外部API集成和Webhook处理,包括HTTP端点路由、请求/响应处理、身份验证、CORS配置和Webhook签名验证
waynesutton
convex-security-check
快速安全审计清单,涵盖身份验证、函数暴露、参数验证、行级访问控制和环境变量处理
waynesutton
firebase-local-env-setup
Bare minimum INITIAL setup for getting started with Firebase (Node.js, CLI installation, first-time login). Use ONLY for first-time setup. For updating, troubleshooting, or refreshing an existing environment, use the firebase-basics skill instead.
firebase
extension-to-functions-codebase
将已安装的 Firebase 扩展(或扩展源代码)转换为独立的 Cloud Functions for Firebase 代码库或可发布的 npm 包,包括将触发器从 V1 升级到 V2,以及配置生命周期钩子和声明式安全性的技能。
firebase
firebase-firestore-enterprise-native-mode
Firestore 企业版原生模式的综合指南,包括配置、数据模型、安全规则和 SDK 使用。当用户需要帮助设置 Firestore 企业版原生模式、编写安全规则或在应用中使用 Firestore SDK 时,使用此技能。
firebase
chrome-webstore-release-blueprint
Guide a user end-to-end through setting up Chrome Web Store API release automation in any repository. Use when asked to walk someone through OAuth/CWS credential setup, refresh token creation, local/CI secret setup, version-based publish automation, and submission status checks.
brianlovin
firebase-auth-basics
设置和使用 Firebase Authentication 的指南。当用户的应用需要用户登录、用户管理或使用身份验证规则保护数据访问时,使用此技能。
firebase
firebase-security-rules-auditor
一个用于评估 Firestore 安全规则安全性的技能。当 Firestore 安全规则更新时使用此技能,以确保生成的规则极其安全且健壮。
firebase
owasp-security
Use when reviewing code for security vulnerabilities, implementing authentication/authorization, handling user input, or discussing web application security. Covers OWASP Top 10:2025, ASVS 5.0, LLM Top 10 (2025), and Agentic AI security (2026).
agamm
penetration-testing
Ethical hacking and security testing methodologies using penetration testing tools, exploit frameworks, and manual security validation. Use when assessing application security posture and identifying exploitable vulnerabilities.
aj-geddes
app-store-review
Evaluates code against Apple's App Store Review Guidelines. Use this skill when reviewing iOS, macOS, tvOS, watchOS, or visionOS app code (Swift, Objective-C, React Native, or Expo) to identify potential App Store rejection issues before submission. Triggers on tasks involving app review preparation, compliance checking, or App Store submission readiness.
safaiyeh
okx-activity
Register for the OKX.AI Trading Hackathon or explain its entry requirements and eligibility. Trigger on requests in any language to register, sign up, join, enter, or participate in the hackathon. Registers an existing Trading ASP; never creates one.
okx
spring-boot-security-jwt
Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based access control using Spring Security 6.x. Use when implementing authentication or authorization in Spring Boot applications.
giuseppe-trisciuoglio
okx-agentic-wallet
OKX Agentic Wallet — 用户钱包与链上执行的单一技能。当用户希望操作钱包或执行链上操作时使用,包括:登录与账户、余额/持仓、钱包地址/充值/收款、发送/转账、合约调用(授权/存款/提现)、交易历史与状态、消息签名、钱包导出与策略;使用稳定币支付Gas(Gas Station,Solana);兑换/交易/买入/卖出/转换、获取报价;跨链桥接与到账跟踪;限价单(抄底/止盈/止损/追涨)及取消/列表/恢复;广播/估算Gas/模拟/跟踪交易;查询任意公开地址的持仓;安全扫描(代币/蜜罐/貔貅、DApp钓鱼、交易与签名检查、授权);审计日志。一旦匹配,遵循本技能的意图路由分发到具体操作。
okx
llm-security
Security guidelines for LLM applications based on OWASP Top 10 for LLM 2025. Use when building LLM apps, reviewing AI security, implementing RAG systems, or asking about LLM vulnerabilities like 'prompt injection' or 'check LLM security'. IMPORTANT: Always consult this skill when building chatbots, AI agents, RAG pipelines, tool-using LLMs, agentic systems, or any application that calls an LLM API (OpenAI, Anthropic, Gemini, etc.) — even if the user doesn't explicitly mention security. Also use when users import 'openai', 'anthropic', 'langchain', 'llamaindex', or similar LLM libraries.
semgrep