安全
安全审查、认证、权限和风险检查
Skills 列表

code-review-and-quality
执行多维度代码审查。在合并任何变更之前使用。在审查自己、其他智能体或人类编写的代码时使用。当需要在代码进入主分支之前从多个维度评估代码质量时使用。
addyosmani
paperclip
Interact with the Paperclip control plane API for task coordination and governance. Use when checking assignments, updating issue status, posting comments, delegating work, managing routines, or calling Paperclip API endpoints.
paperclipai
api-security-best-practices
Implement secure API design patterns including authentication, authorization, input validation, rate limiting, and protection against common API vulnerabilities
sickn33
security-review
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching tools miss. Use this skill when asked to scan code for security vulnerabilities, find bugs, check for SQL injection, XSS, command injection, exposed API keys, hardcoded secrets, insecure dependencies, access control issues, or any request like "is my code secure?", "review for security issues", "audit this codebase", or "check for vulnerabilities". Covers injection flaws, authentication and access control bugs, secrets exposure, weak cryptography, insecure dependencies, and business logic issues across JavaScript, TypeScript, Python, Java, PHP, Go, Ruby, and Rust.
github
copilot-spaces
Use Copilot Spaces to provide project-specific context to conversations. Use this skill when users mention a "Copilot space", want to load context from a shared knowledge base, discover available spaces, or ask questions grounded in curated project documentation, code, and instructions.
github
msstore-cli
Microsoft Store Developer CLI (msstore) for publishing Windows applications to the Microsoft Store. Use when asked to configure Store credentials, list Store apps, check submission status, publish submissions, manage package flights, set up CI/CD for Store publishing, or integrate with Partner Center. Supports Windows App SDK/WinUI, UWP, .NET MAUI, Flutter, Electron, React Native, and PWA applications.
github
mcp-create-declarative-agent
Skill converted from mcp-create-declarative-agent.prompt.md
github
dataverse-python-usecase-builder
Generate complete solutions for specific Dataverse SDK use cases with architecture recommendations
github
entra-agent-user
Create Agent Users in Microsoft Entra ID from Agent Identities, enabling AI agents to act as digital workers with user identity capabilities in Microsoft 365 and Azure environments.
github
git-flow-branch-creator
智能 Git Flow 分支创建器,分析 git status/diff 并根据 nvie Git Flow 分支模型创建合适的分支。
github
architecture-blueprint-generator
全面的项目架构蓝图生成器,可分析代码库以创建详细的架构文档。自动检测技术栈和架构模式,生成可视化图表,记录实现模式,并提供可扩展的蓝图,以维护架构一致性并指导新开发。
github
apple-appstore-reviewer
作为代码库的审查者,负责查找Apple App Store优化或拒绝原因。
github
create-github-action-workflow-specification
为现有的 GitHub Actions CI/CD 工作流创建正式规范,优化用于 AI 消费和工作流维护。
github
azure-devops-cli
通过CLI管理Azure DevOps资源,包括项目、仓库、流水线、构建、拉取请求、工作项、制品和服务终结点。当使用Azure DevOps、az命令、devops自动化、CI/CD,或用户提及Azure DevOps CLI时使用。
github
site-architecture
当用户想要规划、映射或重构网站的页面层级、导航、URL结构或内部链接时使用。也适用于用户提及“站点地图”、“网站地图”、“可视化站点地图”、“网站结构”、“页面层级”、“信息架构”、“IA”、“导航设计”、“URL结构”、“面包屑导航”、“内部链接策略”、“网站规划”、“我需要哪些页面”、“我应该如何组织我的网站”或“网站导航”时。只要有人在规划网站应该有哪些页面以及它们如何连接,就使用此技能。不适用于XML站点地图(那是技术SEO——请参见seo-audit)。对于SEO审计,请参见seo-audit。对于结构化数据,请参见schema。
coreyhaines31
nature-downloader
Use when a user needs lawful academic full text, CNKI institutional access, English OA retrieval, publisher API access, institutional browser fallback, or supporting information downloads.
yuan1z0825
gws-classroom
Google Classroom:管理课程、花名册和课程作业。
googleworkspace
persona-it-admin
管理IT — 监控安全并配置Workspace。
googleworkspace
vercel-optimize
用于对已部署项目(尤其是 Next.js、SvelteKit、Nuxt 以及部分 Astro 应用)进行 Vercel 成本与性能优化。先收集 Vercel 指标、用量、项目配置和代码扫描结果;仅调查有指标支持的候选方案;基于已验证的文件和版本感知的 Vercel/框架文档生成排序后的建议。触发场景:Vercel 账单降低、慢或昂贵的路由、缓存优化机会、函数调用次数、构建分钟数、快速数据传输、Core Web Vitals、Bot Management、Fluid compute 或成本分解请求。
vercel-labs
gws-admin-reports
Google Workspace Admin SDK:审计日志和使用情况报告。
googleworkspace
gws-shared
gws CLI:用于身份验证、全局标志和输出格式化的共享模式。
googleworkspace
gws-keep
管理 Google Keep 笔记。
googleworkspace
ce-proof
Publish, read, comment on, or edit markdown in Proof. Use for Proof links, sharing specs/plans/drafts, or publish handoffs from planning workflows; avoid proofread, math, evidence, or proof-of-concept meanings.
everyinc
ce-simplify-code
Simplify recently changed code for clarity, reuse, quality, and efficiency while preserving behavior. Use for tidy/refactor passes; use ce-debug for bugs.
everyinc