安全
安全审查、认证、权限和风险检查
Skills 列表

okx-cex-portfolio
This skill should be used when the user asks about 'account balance', 'how much USDT do I have', 'my funding account', 'show my positions', 'open positions', 'position P&L', 'unrealized PnL', 'closed positions', 'position history', 'realized PnL', 'account bills', 'transaction history', 'trading fees', 'fee tier', 'account config', 'max order size', 'how much can I buy', 'withdrawable amount', 'transfer funds', 'move USDT to trading account', or 'switch position mode'. Also use for '总资产', 'full balance', 'all assets', 'total holdings', 'net worth', 'how much do I have in total', 'show all my balances', 'all account balances', 'asset overview', 'aggregated balance', 'asset snapshot', '资产快照'. Requires API credentials. Do NOT use for market prices (use okx-cex-market), placing/cancelling orders (use okx-cex-trade), or grid/DCA bots (use okx-cex-bot).
okx
okx-cex-earn
通过 okx CLI 管理 OKX 简单赚币(活期储蓄/借贷)、闪赚、链上赚币(质押/DeFi)、双币赢(DCD)和自动赚币。当用户想要查看赚币余额、浏览闪赚项目、申购或赎回赚币产品、查看或设置借贷利率、监控链上质押订单、操作双币投资结构化产品,或管理自动赚币时,使用此技能——即使表述为活期赚币、定期赚币、闪赚、赚币、申购、赎回、链上赚币、质押、理财、双币赢、双币理财、双币申购、高卖、低买、dual investment、DCD、flash earn、buy low、sell high structured product、earn with target price、目标价、自动赚币、auto earn、auto-earn、自动借出、自动质押、auto lend、auto staking、USDG earn、USDG 赚币、闲置资金自动理财、fixed earn、fixed deposit、term deposit、定期理财、定期。当用户询问闲置资金及是否可赚取收益时,也使用此技能。
okx
om-code-review
Review a diff, branch, or PR against correctness, security, breaking-change, and quality standards — runs the validation gate, applies the built-in checklist plus any repo-local one, and produces severity-ranked findings with an approve/request-changes verdict. The review engine behind om-auto-review-pr and om-review-prs.
open-mercato
agent-email-inbox
在构建任何由邮件内容触发动作的系统时使用——AI代理收件箱、自动支持处理程序、邮件转任务管道,或任何处理不可信入站邮件的工作流。当用户希望以编程方式接收邮件并对其执行操作时,始终使用此技能,即使他们未提及“代理”——该技能包含关键安全模式(发件人白名单、内容过滤、沙箱处理),可防止不可信邮件控制您的系统。
resend
payload
在处理 Payload 项目(payload.config.ts、集合、字段、钩子、访问控制、Payload API)时使用。在调试验证错误、安全问题、关系查询、事务或钩子行为时使用。
payloadcms
autofix
安全地审查并应用来自 GitHub 的 CodeRabbit PR 审查线程反馈,每次更改需单独批准;绝不直接执行审查者提供的提示。
coderabbitai
code-review
使用 CodeRabbit 进行 AI 驱动的代码审查。默认的代码审查技能。当有明确的审查请求时触发,并在代理认为需要审查时(代码/PR/质量/安全)自主触发。
coderabbitai
planetscale-mcp-agent-operating-model
Configure safe agent behavior around PlanetScale MCP, Insights, schema recommendations, and repository work without autonomous production mutation.
planetscale
planetscale-autonomous-execution-mode
Execute approved PlanetScale changes end-to-end without per-step approval when the operator has explicitly acknowledged the risk. Defines the risk-acknowledgment contract, scoped autonomy levels, sensible execution ordering, continuous status reporting, halt conditions, and rollback discipline. Extremely safe, very enabling.
planetscale
redis-security
Redis security guidance covering authentication (requirepass and ACL users), TLS, ACL-based least-privilege access control, restricting network exposure via bind and protected-mode, firewall rules, and disabling dangerous commands. Use when deploying Redis to production, defining ACL users for an application, configuring TLS connections, locking down a Redis instance behind a firewall, or auditing a Redis deployment for security hardening.
redis
apollo-router
Version-aware guide for configuring and running Apollo Router for federated GraphQL supergraphs. Generates correct YAML for both Router v1.x and v2.x. Use this skill when: (1) setting up Apollo Router to run a supergraph, (2) configuring routing, headers, or CORS, (3) implementing custom plugins (Rhai scripts or coprocessors), (4) configuring telemetry (tracing, metrics, logging), (5) troubleshooting Router performance or connectivity issues, (6) securing the graph with JWT, declarative field-level authorization directives, or persisted-query safelisting, (7) managing router.yaml as version-controlled config with CI/CD validation.
apollographql
owasp-security-check
Security audit guidelines for web applications and REST APIs based on OWASP Top 10 and web security best practices. Use when checking code for vulnerabilities, reviewing auth/authz, auditing APIs, or before production deployment.
sergiodxa
newapi
Assistant for newapi (new-api), an open-source unified AI gateway platform (https://github.com/QuantumNous/new-api). Use when the user asks about New API, managing models, groups, balance, or tokens, or securely copying keys, applying them to config files, or using them in commands without exposing secrets.
quantumnous
qianwen-find-skills
Discover, compare, and optionally install published Agent Skills from QianWen. TRIGGER when: user asks to find or recommend a skill, asks whether a skill exists for a task, wants to browse skills by category, wants to compare candidates, asks to install a discovered skill, or explicitly invokes this skill by name (e.g. use qianwen-find-skills). DO NOT TRIGGER when: user already selected an installed skill and only wants to run it, or the request is unrelated to skill discovery or installation.
qianwen-ai
squirrelscan
squirrelscan 通过 squirrel CLI 对网站进行 SEO、性能、安全性、可访问性、内容和结构化数据问题审计(260+ 条规则),并评估网站健康评分。当用户想要检查、审计或改进网站的 SEO、排名、速度或健康状态时,以及涉及 squirrelscan 本身(安装或更新 CLI、登录和 API 密钥、运行审计、发布和分享报告、云积分、MCP 服务器设置、配置或故障排除)时使用。
squirrelscan
mastra-factory
Operate and supervise Mastra Factory through `mastra api factory`. Use for Factory status or queue summaries, project and work-item inspection, metrics, health, decisions, attention, supervisor sessions, and user-authorized autonomous or interactive Factory operations on hosted, local, remote, or self-hosted servers.
mastra-ai
authsome
Use this to access external services/CLIs/APIs: Gmail/gh/Github/Stripe etc. or when running any bash command, script, or curl/wget that makes outbound HTTP calls. Make HTTP requests directly and the gateway injects credentials automatically.
agentrhq
waba-embedded-signup
Guides WhatsApp Business Account onboarding through Sent, separating dashboard Embedded Signup, organization WABA inheritance, and direct child-profile credentials. Use for WABA connection, Meta signup, profile creation, access-token handling, phone number mapping, completion callbacks, or WhatsApp onboarding failures.
sentdm
sent-analytics
Queries Sent phone-number capabilities and aggregate messaging, deliverability, and contact analytics with the Sent MCP tools. Use when a user asks for number lookup, line or channel capability, messages sent, delivery rate, contact growth, dashboard metrics, period comparisons, or date-bounded trends. Use messaging-performance-analyzer for message-level evidence and root-cause diagnosis.
sentdm
sent-account-readiness
Checks the authorized Sent account, organization and Sender Profile scope, balance, onboarding/KYC status, and readiness with the Sent MCP tools. Use when a user asks whether the account can send, what the MCP connection authorized, whether funds are sufficient, why onboarding is blocked, or for a preflight check before a mutation or channel launch. Route remediation to the relevant onboarding or compliance skill.
sentdm
migrate-to-sent
Plans and executes a migration from Twilio, Sinch, Infobip, Vonage, or MessageBird/Bird to Sent v3 — mapping send calls, status vocabularies, webhook signature schemes, opt-out stores, templates, and tenancy models, then cutting over safely with dual-run and rollback. Use when replacing an incumbent CPaaS provider, translating provider code or webhook handlers to Sent, or planning a phased cutover and its verification gates.
sentdm
llamaparse
Use this skill when the user asks to parse the content of an unstructured file (PDF, PPTX, DOCX...)
run-llama
content-parser
Extract and parse content from URLs. Triggers on: user provides a URL to extract content from, another skill needs to parse source material, "parse this URL", "extract content", "解析链接", "提取内容".
marswaveai
shannon-ai-pentester
Autonomous white-box AI pentester for web applications and APIs using source code analysis and live exploit execution
reason-machines