安全

安全审查、认证、权限和风险检查

599 个 Skills 可用

Skills 列表

quarkus-security

quarkus-security

240Ksecurity

Quarkus Security best practices for authentication, authorization, JWT/OIDC, RBAC, input validation, CSRF, secrets management, and dependency security. Use when reviewing Quarkus authn/authz, JWT or OIDC, RBAC, validation, or secrets.

affaan-m avataraffaan-m
获取
enterprise-agent-ops

enterprise-agent-ops

239Ksecurity

Operate long-lived agent workloads with observability, security boundaries, and lifecycle management.

affaan-m avataraffaan-m
获取
x-api

x-api

239Ksecurity

X/Twitter API integration for posting tweets, threads, reading timelines, search, and analytics. Covers OAuth auth patterns, rate limits, and platform-native content posting. Use when the user wants to interact with X programmatically.

affaan-m avataraffaan-m
获取
returns-reverse-logistics

returns-reverse-logistics

239Ksecurity

Codified expertise for returns authorization, receipt and inspection, disposition decisions, refund processing, fraud detection, and warranty claims management. Informed by returns operations managers with 15+ years experience. Includes grading frameworks, disposition economics, fraud pattern recognition, and vendor recovery processes. Use when handling product returns, reverse logistics, refund decisions, return fraud detection, or warranty claims.

affaan-m avataraffaan-m
获取
healthcare-phi-compliance

healthcare-phi-compliance

239Ksecurity

Protected Health Information (PHI) and Personally Identifiable Information (PII) compliance patterns for healthcare applications. Covers data classification, access control, audit trails, encryption, and common leak vectors.

affaan-m avataraffaan-m
获取
laravel-plugin-discovery

laravel-plugin-discovery

239Ksecurity

Discover and evaluate Laravel packages via LaraPlugins.io MCP. Use when the user wants to find plugins, check package health, or assess Laravel/PHP compatibility.

affaan-m avataraffaan-m
获取
security-bounty-hunter

security-bounty-hunter

239Ksecurity

Hunt for exploitable, bounty-worthy security issues in repositories. Focuses on remotely reachable vulnerabilities that qualify for real reports instead of noisy local-only findings.

affaan-m avataraffaan-m
获取
github-ops

github-ops

239Ksecurity

GitHub repository operations, automation, and management. Issue triage, PR management, CI/CD operations, release management, and security monitoring using the gh CLI. Use when the user wants to manage GitHub issues, PRs, CI status, releases, contributors, stale items, or any GitHub operational task beyond simple git commands.

affaan-m avataraffaan-m
获取
security-review

security-review

239Ksecurity

Use this skill when adding authentication, handling user input, working with secrets, creating API endpoints, or implementing payment/sensitive features. Provides comprehensive security checklist and patterns.

affaan-m avataraffaan-m
获取
django-security

django-security

239Ksecurity

Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

affaan-m avataraffaan-m
获取
springboot-security

springboot-security

239Ksecurity

Spring Security best practices for authn/authz, validation, CSRF, secrets, headers, rate limiting, and dependency security in Java Spring Boot services.

affaan-m avataraffaan-m
获取
laravel-security

laravel-security

239Ksecurity

Laravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations.

affaan-m avataraffaan-m
获取
network-config-validation

network-config-validation

237Ksecurity

路由器与交换机上线前的配置检查工具,涵盖高危命令检测、IP 地址重复、子网重叠、失效引用、管理平面风险以及 IOS 风格的安全规范校验。

affaan-m avataraffaan-m
获取
quarkus-security

quarkus-security

237Ksecurity

Quarkus 安全最佳实践,涵盖身份验证、授权、JWT/OIDC、RBAC、输入校验、CSRF 防护、密钥管理及依赖项安全。

affaan-m avataraffaan-m
获取
netmiko-ssh-automation

netmiko-ssh-automation

237Ksecurity

安全的 Python Netmiko 实战范例,涵盖只读信息采集、限流批量 SSH 连接、TextFSM 结构化解析、带防护机制的配置变更、超时设置以及网络自动化错误处理。

affaan-m avataraffaan-m
获取
fastapi-patterns

fastapi-patterns

237Ksecurity

FastAPI 最佳实践指南,涵盖项目结构规划、Pydantic v2 数据 Schema、依赖注入、异步处理函数(Async Handlers)、身份认证与鉴权、带事务控制的服务层,以及基于 httpx 和 pytest 的自动化测试。

affaan-m avataraffaan-m
获取
mysql-patterns

mysql-patterns

237Ksecurity

适用于生产环境后端设计的 MySQL 与 MariaDB 表结构、查询优化、索引设计、事务处理、主从复制及连接池最佳实践与常见模式。

affaan-m avataraffaan-m
获取
production-audit

production-audit

237Ksecurity

基于本地证据的生产环境就绪度审计,适用于已上线应用评估、发布前审查、合并后检查,以及排查“上线后会踩什么坑/生产环境会出什么故障?”等问题。全程无需将代码库数据发送到第三方审计服务。

affaan-m avataraffaan-m
获取
defi-amm-security

defi-amm-security

232Ksecurity

针对Solidity AMM合约、流动性池和交换流程的安全检查清单。涵盖重入攻击、CEI顺序、捐赠或通胀攻击、预言机操纵、滑点、管理员控制和整数运算。

affaan-m avataraffaan-m
获取
github-ops

github-ops

232Ksecurity

GitHub 仓库操作、自动化与管理。包括问题分类、PR 管理、CI/CD 操作、发布管理以及使用 gh CLI 进行安全监控。当用户想要管理 GitHub 问题、PR、CI 状态、发布、贡献者、过期项或任何超出简单 git 命令的 GitHub 操作任务时使用。

affaan-m avataraffaan-m
获取
hipaa-compliance

hipaa-compliance

232Ksecurity

HIPAA专用入口,用于医疗隐私与安全工作。当任务明确涉及HIPAA、PHI处理、受保实体、BAA、违规态势或美国医疗合规要求时使用。

affaan-m avataraffaan-m
获取
security-bounty-hunter

security-bounty-hunter

232Ksecurity

在仓库中寻找可利用、值得领取赏金的安全问题。专注于远程可触达的漏洞,这些漏洞符合真实报告的条件,而非嘈杂的仅本地发现。

affaan-m avataraffaan-m
获取
healthcare-phi-compliance

healthcare-phi-compliance

231Ksecurity

医疗应用中受保护健康信息(PHI)和个人身份信息(PII)的合规模式。涵盖数据分类、访问控制、审计追踪、加密及常见泄露向量。

affaan-m avataraffaan-m
获取
laravel-plugin-discovery

laravel-plugin-discovery

231Ksecurity

通过 LaraPlugins.io MCP 发现和评估 Laravel 包。当用户想要查找插件、检查包健康状况或评估 Laravel/PHP 兼容性时使用。

affaan-m avataraffaan-m
获取