安全

安全审查、认证、权限和风险检查

599 个 Skills 可用

Skills 列表

security-auditor

security-auditor

78security

Security vulnerability expert covering OWASP Top 10 and common security issues. Use when conducting security audits or reviewing code for vulnerabilities.

zhaono1 avatarzhaono1
获取
cybersecurity-analyst

cybersecurity-analyst

77security

Analyzes events through cybersecurity lens using threat modeling, attack surface analysis, defense-in-depth, zero-trust architecture, and risk-based frameworks (CIA triad, STRIDE, MITRE ATT&CK). Provides insights on vulnerabilities, attack vectors, defense strategies, incident response, and security posture. Use when: Security incidents, vulnerability assessments, threat analysis, security architecture, compliance. Evaluates: Confidentiality, integrity, availability, threat actors, attack patterns, controls, residual risk.

rysweet avatarrysweet
获取
ci-cd-security

ci-cd-security

76security

扫描 GitHub Actions 工作流文件中的安全漏洞,通过直接读取 YAML 并报告发现结果——无需外部工具、无需安装、无需执行 shell 命令。当用户分享 `.github/workflows/` 文件、粘贴工作流 YAML、请求 CI/CD 安全审查、提及 `pull_request_target`、`workflow_run`、操作固定、`GITHUB_TOKEN` 权限、pwn 请求、模板注入、缓存投毒、秘密泄露、供应链风险或任何 GitHub Actions 加固主题时,使用此技能。当用户正在加固开源仓库、进行 CI/CD 红队评估、评估供应链扫描目标或公开撰写 CI/CD 安全相关内容时,也触发此技能。倾向于触发此技能而非凭记忆回答——CI/CD 安全默认值几乎在所有地方都是错误的,且规则不直观。

superagent-ai avatarsuperagent-ai
获取
cloudbase-document-database-in-wechat-miniprogram

cloudbase-document-database-in-wechat-miniprogram

75security

Use CloudBase document database WeChat MiniProgram SDK to query, create, update, and delete data. Supports complex queries, pagination, aggregation, and geolocation queries.

tencentcloudbase avatartencentcloudbase
获取
mapbox-ios-patterns

mapbox-ios-patterns

75security

Official integration patterns for Mapbox Maps SDK on iOS. Covers installation, adding markers, user location, custom data, styles, camera control, and featureset interactions. Based on official Mapbox documentation.

mapbox avatarmapbox
获取
mapbox-google-maps-migration

mapbox-google-maps-migration

75security

Migration guide for developers moving from Google Maps Platform to Mapbox GL JS, covering API equivalents, pattern translations, and key differences

mapbox avatarmapbox
获取
authsome

authsome

73security

Use this to access external services/CLIs/APIs: Gmail/gh/Github/Stripe etc. or when running any bash command, script, or curl/wget that makes outbound HTTP calls. Make HTTP requests directly and the gateway injects credentials automatically.

manojbajaj95 avatarmanojbajaj95
获取
mapbox-token-security

mapbox-token-security

73security

Security best practices for Mapbox access tokens, including scope management, URL restrictions, rotation strategies, and protecting sensitive data. Use when creating, managing, or advising on Mapbox token security.

mapbox avatarmapbox
获取
claude-for-safari

claude-for-safari

73security

Control the user's real Safari browser on macOS through AppleScript, page JavaScript, screenshots, and carefully verified System Events input. Use when an agent needs to inspect or operate the user's existing Safari tabs and login sessions, including reading pages, navigating, clicking, filling non-sensitive forms, taking screenshots, observing page-level fetch/XHR metadata, or troubleshooting Safari-specific UI behavior.

sdlll avatarsdlll
获取
auth-wechat-miniprogram

auth-wechat-miniprogram

72security

CloudBase WeChat Mini Program native authentication guide. This skill should be used when users need mini program identity handling, OPENID/UNIONID access, or `wx.cloud` auth behavior in projects where login is native and automatic.

tencentcloudbase avatartencentcloudbase
获取
capacitor-security

capacitor-security

71security

Comprehensive security guide for Capacitor apps using Capsec scanner. Covers 63+ security rules across secrets, storage, network, authentication, cryptography, and platform-specific vulnerabilities. Use this skill when users need to secure their mobile app or run security audits.

cap-go avatarcap-go
获取
openclaw-secure-linux-cloud

openclaw-secure-linux-cloud

65security

当您在云服务器上自托管 OpenClaw、加固远程 OpenClaw 网关、选择 SSH 隧道、Tailscale 或反向代理暴露方式,或审查 Podman、配对、沙箱、令牌认证和工具权限默认设置以确保安全个人部署时使用。

xixu-me avatarxixu-me
获取
opensource-guide-coach

opensource-guide-coach

65security

Use when a user wants guidance on starting, contributing to, growing, governing, funding, securing, or sustaining an open source project, or asks about contributor onboarding, community health, maintainer burnout, code of conduct, metrics, legal basics, or open source project adoption.

xixu-me avatarxixu-me
获取
running-claude-code-via-litellm-copilot

running-claude-code-via-litellm-copilot

65security

当需要通过本地 LiteLLM 代理将 Claude Code 路由到 GitHub Copilot、减少直接 Anthropic 开销、配置 ANTHROPIC_BASE_URL 或 ANTHROPIC_MODEL 覆盖,或排查 Copilot 代理设置失败(如模型未找到、无本地流量、GitHub 401/403 认证错误)时使用。

xixu-me avatarxixu-me
获取
feishu-calendar

feishu-calendar

65security

飞书日历。创建日程、查询日程、更新日程。

alextangson avataralextangson
获取
skill-vetter

skill-vetter

64security

面向OpenClaw技能的安全优先审查工具。在从ClawHub、GitHub或其他来源安装任何技能前使用。

useai-pro avataruseai-pro
获取
clerk-swift

clerk-swift

63security

Implement Clerk authentication for native Swift and iOS apps using ClerkKit

clerk avatarclerk
获取
clerk-android

clerk-android

63security

使用 Kotlin 和 Jetpack Compose 为原生 Android 应用实现 Clerk 身份验证,遵循 clerk-android 源码引导模式。可用于预构建的 AuthView/UserButton 或自定义 API 驱动的认证流程。不适用于 Expo 或 React Native 项目。

clerk avatarclerk
获取
capacitor-best-practices

capacitor-best-practices

58security

Best practices for Capacitor app development including project structure, plugin usage, performance optimization, security, and deployment. Use this skill when reviewing Capacitor code, setting up new projects, or optimizing existing apps.

cap-go avatarcap-go
获取
qianwen-video-generation

qianwen-video-generation

57security

[QianWen] Generate videos using Wan models. Supports text-to-video, image-to-video, first+last frame, reference-based role-play, and video editing (VACE). TRIGGER when: user wants to create, generate, or edit video content, mentions video generation/animation/video clips/Wan models, or explicitly invokes this skill by name (e.g. use qianwen-video-generation). DO NOT TRIGGER when: user wants to generate images (use qianwen-image-generation), understand/analyze existing videos (use qianwen-vision), text-only tasks.

qianwen-ai avatarqianwen-ai
获取
qianwen-ops-auth

qianwen-ops-auth

57security

[QianWen] Configure authentication (API keys, endpoints). TRIGGER when: setting up QIANWEN_API_KEY, troubleshooting 401/auth errors, when another skill reports missing credentials, or user explicitly invokes this skill by name (e.g. use qianwen-ops-auth). DO NOT TRIGGER when: non-auth Qwen tasks, general API usage questions.

qianwen-ai avatarqianwen-ai
获取
ui-design-review

ui-design-review

53design-ui

Comprehensive visual design and aesthetics evaluation. Analyzes typography, color, spacing, hierarchy, consistency, branding, and current product-category conventions for polished, professional interfaces.

mastepanoski avatarmastepanoski
获取
wcag-accessibility-audit

wcag-accessibility-audit

52design-ui

Comprehensive web accessibility audit using WCAG 2.1/2.2 guidelines. Evaluate compliance across 4 POUR principles (Perceivable, Operable, Understandable, Robust) with A, AA, AAA conformance levels.

mastepanoski avatarmastepanoski
获取
10x-cli-setup

10x-cli-setup

49security

ALWAYS invoke this skill when the user mentions 10x-cli, @przeprogramowani/10x-cli, the 10xDevs CLI, or the 10xDevs course environment in a setup context. This skill fetches the live README — Claude does not know 10x-cli's current install steps without it. Applies to: installing, updating, reconfiguring for different AI tools (Cursor, Copilot, Claude Code), permission/npm errors, authentication, and onboarding after 10xDevs enrollment. Excludes: developing 10x-cli source code, contributing to the repo, building similar CLIs, or general project setup.

przeprogramowani avatarprzeprogramowani
获取