安全

安全审查、认证、权限和风险检查

599 个 Skills 可用

Skills 列表

okx-cex-portfolio

okx-cex-portfolio

155security

This skill should be used when the user asks about 'account balance', 'how much USDT do I have', 'my funding account', 'show my positions', 'open positions', 'position P&L', 'unrealized PnL', 'closed positions', 'position history', 'realized PnL', 'account bills', 'transaction history', 'trading fees', 'fee tier', 'account config', 'max order size', 'how much can I buy', 'withdrawable amount', 'transfer funds', 'move USDT to trading account', or 'switch position mode'. Also use for '总资产', 'full balance', 'all assets', 'total holdings', 'net worth', 'how much do I have in total', 'show all my balances', 'all account balances', 'asset overview', 'aggregated balance', 'asset snapshot', '资产快照'. Requires API credentials. Do NOT use for market prices (use okx-cex-market), placing/cancelling orders (use okx-cex-trade), or grid/DCA bots (use okx-cex-bot).

okx avatarokx
获取
okx-cex-earn

okx-cex-earn

155security

通过 okx CLI 管理 OKX 简单赚币(活期储蓄/借贷)、闪赚、链上赚币(质押/DeFi)、双币赢(DCD)和自动赚币。当用户想要查看赚币余额、浏览闪赚项目、申购或赎回赚币产品、查看或设置借贷利率、监控链上质押订单、操作双币投资结构化产品,或管理自动赚币时,使用此技能——即使表述为活期赚币、定期赚币、闪赚、赚币、申购、赎回、链上赚币、质押、理财、双币赢、双币理财、双币申购、高卖、低买、dual investment、DCD、flash earn、buy low、sell high structured product、earn with target price、目标价、自动赚币、auto earn、auto-earn、自动借出、自动质押、auto lend、auto staking、USDG earn、USDG 赚币、闲置资金自动理财、fixed earn、fixed deposit、term deposit、定期理财、定期。当用户询问闲置资金及是否可赚取收益时,也使用此技能。

okx avatarokx
获取
om-code-review

om-code-review

149security

Review a diff, branch, or PR against correctness, security, breaking-change, and quality standards — runs the validation gate, applies the built-in checklist plus any repo-local one, and produces severity-ranked findings with an approve/request-changes verdict. The review engine behind om-auto-review-pr and om-review-prs.

open-mercato avataropen-mercato
获取
agent-email-inbox

agent-email-inbox

148security

在构建任何由邮件内容触发动作的系统时使用——AI代理收件箱、自动支持处理程序、邮件转任务管道,或任何处理不可信入站邮件的工作流。当用户希望以编程方式接收邮件并对其执行操作时,始终使用此技能,即使他们未提及“代理”——该技能包含关键安全模式(发件人白名单、内容过滤、沙箱处理),可防止不可信邮件控制您的系统。

resend avatarresend
获取
payload

payload

135security

在处理 Payload 项目(payload.config.ts、集合、字段、钩子、访问控制、Payload API)时使用。在调试验证错误、安全问题、关系查询、事务或钩子行为时使用。

payloadcms avatarpayloadcms
获取
autofix

autofix

129security

安全地审查并应用来自 GitHub 的 CodeRabbit PR 审查线程反馈,每次更改需单独批准;绝不直接执行审查者提供的提示。

coderabbitai avatarcoderabbitai
获取
code-review

code-review

126security

使用 CodeRabbit 进行 AI 驱动的代码审查。默认的代码审查技能。当有明确的审查请求时触发,并在代理认为需要审查时(代码/PR/质量/安全)自主触发。

coderabbitai avatarcoderabbitai
获取
planetscale-mcp-agent-operating-model

planetscale-mcp-agent-operating-model

126security

Configure safe agent behavior around PlanetScale MCP, Insights, schema recommendations, and repository work without autonomous production mutation.

planetscale avatarplanetscale
获取
planetscale-autonomous-execution-mode

planetscale-autonomous-execution-mode

126security

Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk. Defines the risk-acknowledgment contract, scoped autonomy levels, sensible execution ordering, continuous status reporting, halt conditions, and rollback discipline. Extremely safe, very enabling.

planetscale avatarplanetscale
获取
redis-security

redis-security

125security

Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules, and disabling dangerous commands. Use when deploying Redis to production, defining ACL users for an application, configuring TLS connections, locking down a Redis instance behind a firewall, or auditing a Redis deployment for security hardening.

redis avatarredis
获取
apollo-router

apollo-router

108security

Version-aware guide for configuring and running Apollo Router for federated GraphQL supergraphs. Generates correct YAML for both Router v1.x and v2.x. Use this skill when: (1) setting up Apollo Router to run a supergraph, (2) configuring routing, headers, or CORS, (3) implementing custom plugins (Rhai scripts or coprocessors), (4) configuring telemetry (tracing, metrics, logging), (5) troubleshooting Router performance or connectivity issues, (6) securing the graph with JWT, declarative field-level authorization directives, or persisted-query safelisting, (7) managing router.yaml as version-controlled config with CI/CD validation.

apollographql avatarapollographql
获取
owasp-security-check

owasp-security-check

91security

Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.

sergiodxa avatarsergiodxa
获取
newapi

newapi

88security

Assistant for newapi (new-api), an open-source unified AI gateway platform (https://github.com/QuantumNous/new-api). Use when the user asks about New API, managing models, groups, balance, or tokens, or securely copying keys, applying them to config files, or using them in commands without exposing secrets.

quantumnous avatarquantumnous
获取
qianwen-find-skills

qianwen-find-skills

87security

Discover, compare, and optionally install published Agent Skills from QianWen. TRIGGER when: user asks to find or recommend a skill, asks whether a skill exists for a task, wants to browse skills by category, wants to compare candidates, asks to install a discovered skill, or explicitly invokes this skill by name (e.g. use qianwen-find-skills). DO NOT TRIGGER when: user already selected an installed skill and only wants to run it, or the request is unrelated to skill discovery or installation.

qianwen-ai avatarqianwen-ai
获取
squirrelscan

squirrelscan

85security

squirrelscan 通过 squirrel CLI 对网站进行 SEO、性能、安全性、可访问性、内容和结构化数据问题审计(260+ 条规则),并评估网站健康评分。当用户想要检查、审计或改进网站的 SEO、排名、速度或健康状态时,以及涉及 squirrelscan 本身(安装或更新 CLI、登录和 API 密钥、运行审计、发布和分享报告、云积分、MCP 服务器设置、配置或故障排除)时使用。

squirrelscan avatarsquirrelscan
获取
mastra-factory

mastra-factory

85security

Operate and supervise Mastra Factory through `mastra api factory`. Use for Factory status or queue summaries, project and work-item inspection, metrics, health, decisions, attention, supervisor sessions, and user-authorized autonomous or interactive Factory operations on hosted, local, remote, or self-hosted servers.

mastra-ai avatarmastra-ai
获取
authsome

authsome

79security

Use this to access external services/CLIs/APIs: Gmail/gh/Github/Stripe etc. or when running any bash command, script, or curl/wget that makes outbound HTTP calls. Make HTTP requests directly and the gateway injects credentials automatically.

agentrhq avataragentrhq
获取
waba-embedded-signup

waba-embedded-signup

79security

Guides WhatsApp Business Account onboarding through Sent, separating dashboard Embedded Signup, organization WABA inheritance, and direct child-profile credentials. Use for WABA connection, Meta signup, profile creation, access-token handling, phone number mapping, completion callbacks, or WhatsApp onboarding failures.

sentdm avatarsentdm
获取
sent-analytics

sent-analytics

79security

Queries Sent phone-number capabilities and aggregate messaging, deliverability, and contact analytics with the Sent MCP tools. Use when a user asks for number lookup, line or channel capability, messages sent, delivery rate, contact growth, dashboard metrics, period comparisons, or date-bounded trends. Use messaging-performance-analyzer for message-level evidence and root-cause diagnosis.

sentdm avatarsentdm
获取
sent-account-readiness

sent-account-readiness

79security

Checks the authorized Sent account, organization and Sender Profile scope, balance, onboarding/KYC status, and readiness with the Sent MCP tools. Use when a user asks whether the account can send, what the MCP connection authorized, whether funds are sufficient, why onboarding is blocked, or for a preflight check before a mutation or channel launch. Route remediation to the relevant onboarding or compliance skill.

sentdm avatarsentdm
获取
migrate-to-sent

migrate-to-sent

79security

Plans and executes a migration from Twilio, Sinch, Infobip, Vonage, or MessageBird/Bird to Sent v3 — mapping send calls, status vocabularies, webhook signature schemes, opt-out stores, templates, and tenancy models, then cutting over safely with dual-run and rollback. Use when replacing an incumbent CPaaS provider, translating provider code or webhook handlers to Sent, or planning a phased cutover and its verification gates.

sentdm avatarsentdm
获取
llamaparse

llamaparse

78security

Use this skill when the user asks to parse the content of an unstructured file (PDF, PPTX, DOCX...)

run-llama avatarrun-llama
获取
content-parser

content-parser

78security

Extract and parse content from URLs. Triggers on: user provides a URL to extract content from, another skill needs to parse source material, "parse this URL", "extract content", "解析链接", "提取内容".

marswaveai avatarmarswaveai
获取
shannon-ai-pentester

shannon-ai-pentester

78security

Autonomous white-box AI pentester for web applications and APIs using source code analysis and live exploit execution

reason-machines avatarreason-machines
获取