安全

安全审查、认证、权限和风险检查

599 个 Skills 可用

Skills 列表

semgrep

semgrep

283testing-qa

Run Semgrep static analysis scans and create custom detection rules. Use when asked to scan code with Semgrep, find security vulnerabilities, write custom YAML rules, or detect specific bug patterns. IMPORTANT: Also use this skill when users ask to 'scan for bugs', 'check code quality', 'find vulnerabilities', 'static analysis', 'lint for security', 'audit this code', or want to enforce coding standards — even if they don't mention Semgrep by name. Semgrep is the right tool for pattern-based code scanning across 30+ languages.

semgrep avatarsemgrep
获取
code-security

code-security

268devops-cloud

Security guidelines for writing secure code. Use when writing code, reviewing code for vulnerabilities, or asking about secure coding practices like 'check for SQL injection' or 'review security'. IMPORTANT: Always consult this skill when writing or reviewing any code that handles user input, authentication, file operations, database queries, network requests, cryptography, or infrastructure configuration (Terraform, Kubernetes, Docker, GitHub Actions) — even if the user doesn't explicitly mention security. Also use when users ask to 'review my code', 'check this for bugs', or 'is this safe'.

semgrep avatarsemgrep
获取
onedrive

onedrive

264security

MS OneDrive integration. Manage Accounts. Use when the user wants to interact with MS OneDrive data.

membranedev avatarmembranedev
获取
nextauth-authentication

nextauth-authentication

259security

Guidelines for implementing NextAuth.js (Auth.js v5) authentication in Next.js applications with session management and security best practices

mindrally avatarmindrally
获取
kafka-development

kafka-development

259security

Best practices for Apache Kafka event streaming and distributed messaging. Use when building event-driven architectures, implementing producer/consumer patterns, designing topic partitioning strategies, setting up Kafka Streams, configuring schema registries, or integrating change data capture pipelines.

mindrally avatarmindrally
获取
gitlab-workflow

gitlab-workflow

259security

GitLab best practices for merge requests, CI/CD pipelines, issue tracking, and DevOps workflows

mindrally avatarmindrally
获取
rabbitmq-development

rabbitmq-development

259security

Best practices and guidelines for RabbitMQ message queue development with AMQP protocol

mindrally avatarmindrally
获取
owasp-security

owasp-security

257security

遵循 OWASP Top 10 实施安全编码实践。用于预防安全漏洞、实现身份验证、保护 API 或进行安全审查。触发词:OWASP、安全、XSS、SQL 注入、CSRF、身份验证安全、安全编码、漏洞。

hoodini avatarhoodini
获取
google-drive

google-drive

252security

Google Drive integration. Manage Drives, Users, Permissions. Use when the user wants to interact with Google Drive data.

membranedev avatarmembranedev
获取
jwt-security

jwt-security

245security

Guidelines for implementing JWT authentication with security best practices for token creation, validation, and storage

mindrally avatarmindrally
获取
check-npm

check-npm

240security

Audit a JavaScript/TypeScript repo's npm, yarn, or pnpm configuration for supply-chain hardening: tool version, lifecycle scripts, unsafe dependency protocols, and minimum release age ≥3 days. Use when the user invokes /check-npm or asks to audit package manager security, lifecycle scripts, git dependencies, ignore-scripts, min-release-age, allow-git, approvedGitRepositories, strictDepBuilds, or blockExoticSubdeps in a Grafana plugin or JS/TS project.

grafana avatargrafana
获取
code-review-pro

code-review-pro

234security

全面的代码审查,涵盖安全漏洞、性能瓶颈、最佳实践和重构机会。当用户请求代码审查、安全审计或性能分析时使用。

onewave-ai avataronewave-ai
获取
v4-security-foundations

v4-security-foundations

230security

Security-first Uniswap v4 hook development. Use when user mentions "v4 hooks", "hook security", "PoolManager", "beforeSwap", "afterSwap", or asks about V4 hook best practices, vulnerabilities, or audit requirements.

uniswap avataruniswap
获取
ui-components

ui-components

225frontend

UI component library patterns for shadcn/ui and Radix Primitives. Use when building accessible component libraries, customizing shadcn components, using Radix unstyled primitives, or creating design system foundations.

yonatangross avataryonatangross
获取
zsxq-shared

zsxq-shared

222security

知识星球 CLI 共享基础:认证登录(auth login/logout/status)、配置诊断(doctor/config show)、通用 API 调用规范(api list/api call/api raw 调用底层接口或原始 HTTP 接口)、星球与主题分享链接拼接(电脑端 / 手机端)、写入与删除操作的安全规则、常见错误码处理(401 token 过期、缺参数等)。当用户首次登录、退出登录、查看认证状态、调用 zsxq-cli api raw / api call、需要拼接知识星球分享链接,或遇到认证或 HTTP 错误时使用。

unnoo avatarunnoo
获取
redis-best-practices

redis-best-practices

220security

Redis development best practices for caching, data structures, and high-performance key-value operations

mindrally avatarmindrally
获取
oncall-irm

oncall-irm

212security

Route alerts, run on-call rotations, and drive incidents in Grafana IRM / OnCall — integrations (Alertmanager / Grafana Alerting / generic webhook / PagerDuty), Jinja2 routing + grouping templates, escalation chains (wait → notify schedule → notify team → webhook → auto-resolve), schedules (web + iCal + Terraform `grafana_oncall_schedule`), Slack chatops with Acknowledge/Resolve/Silence, and the P1-P4 incident lifecycle. Use when wiring Alertmanager to OnCall, deciding which team gets paged, building rotations from a Google Calendar / iCal, hooking up Slack notifications, or declaring an incident from an alert — even when the user says "page the platform team on critical alerts", "send Prometheus alerts to Slack", "set up our on-call rota", "escalation policy", or "auto-resolve when the alert clears" without naming OnCall / IRM. Heads up — OnCall OSS is in maintenance mode (archived March 2026); Grafana Cloud users should use IRM.

grafana avatargrafana
获取
prd-generator

prd-generator

208security

Generate comprehensive Product Requirements Documents (PRDs) for product managers. Use this skill when users ask to "create a PRD", "write product requirements", "document a feature", or need help structuring product specifications.

jamesrochabrun avatarjamesrochabrun
获取
nestjs-best-practices

nestjs-best-practices

203security

NestJS 最佳实践与架构模式,用于构建生产级应用。在编写、审查或重构 NestJS 代码时,应使用此技能以确保模块、依赖注入、安全性和性能的正确模式。

kadajett avatarkadajett
获取
grafana-oss

grafana-oss

203security

配置 Grafana OSS — 通过 YAML 配置仪表盘,设置数据源(Prometheus / Loki / Tempo / Pyroscope),编写带模板变量的仪表盘 JSON,构建面板查询,分配内置角色(Viewer / Editor / Admin / GrafanaAdmin),生成服务账户令牌,编辑 grafana.ini 服务器配置,创建注释,通过配置安装插件,并使用健康检查 curl 验证每一步。适用于构建仪表盘、配置数据源、设置配置 YAML、选择面板类型、编写模板变量、管理用户和角色、在 grafana.ini 中配置 SMTP/OAuth、通过 API 创建注释、排查配置的仪表盘未显示的问题,或在本地运行 Grafana OSS — 即使用户只说“设置 Prometheus 数据源”、“从 git 配置仪表盘”、“创建服务账户”或“在 OSS 中配置 SSO”而未提及“Grafana OSS”。

grafana avatargrafana
获取
mongodb-mcp-setup

mongodb-mcp-setup

164security

Guide users through configuring key MongoDB MCP server options. Use this skill when a user has the MongoDB MCP server installed but hasn't configured the required environment variables, or when they ask about connecting to MongoDB/Atlas and don't have the credentials set up.

mongodb avatarmongodb
获取
earn-hunter

earn-hunter

161security

Automatically monitors OKX Flash Earn, Fixed Earn and Flexible Earn opportunities, sends push notifications, and guides subscription. 自动监控 OKX 闪赚、定期和活期赚币机会,推送通知并引导申购。Use when user says: 有闪赚通知我, 监控赚币, monitor earn, notify me about earn, 定时检查理财, 执行 earn-hunter 扫描, earn-hunter scan, 活期年化高了通知我, 监控活期.

okx avatarokx
获取
okx-cex-smartmoney

okx-cex-smartmoney

156security

Smart Money analytics on OKX: leaderboard traders, position tracking, trade records, closed-position history, aggregated consensus signals, and signal history. Use this skill when the user asks about 聪明钱, smart money, 牛人榜, leaderboard, top traders, 交易员排行, trader ranking, trader positions, trader PnL, 交易员持仓, 交易员收益, 历史平仓, closed positions, realized PnL track record, trade history, 成交记录, smart money signal, 聪明钱信号, long/short ratio, 多空比, capital flow, 资金流向, position conviction, 仓位强度, entry price distribution, smart money overview, 聪明钱总览, signal history, 信号历史, trader search, 搜索交易员, who is trading BTC, 谁在交易BTC, recommend traders, 推荐交易员, best traders, top performers.

okx avatarokx
获取
okx-cex-trade

okx-cex-trade

155security

Use when the user asks to 'buy BTC', 'sell ETH', 'place a limit order', 'place a market order', 'cancel my order', 'amend my order', 'long BTC perp', 'short ETH swap', 'open a position', 'close a position', 'set take profit', 'limit take profit', 'immediate TP', 'set stop loss', 'self-trade prevention', 'stpMode', 'auto-cancel on close', 'trailing stop', 'pending order', 'chase order', 'iceberg', 'TWAP', 'split order', 'large order', 'set leverage', 'check my orders', 'fill history', 'buy a call', 'sell a put', 'option chain', 'implied volatility', 'IV', 'Greeks', 'delta', 'gamma', 'event contract', 'buy Yes', 'buy No', 'buy Up', 'buy Down', 'prediction market', or any request to place, cancel, or amend spot, swap, futures, options, or event contract orders on OKX CEX. Covers conditional (TP/SL/trailing) algo orders. Requires API credentials. Do NOT use for market data (okx-cex-market), account balance (okx-cex-portfolio), or bots (okx-cex-bot).

okx avatarokx
获取