安全

安全审查、认证、权限和风险检查

599 个 Skills 可用

Skills 列表

what-an-email-reveals

what-an-email-reveals

21testing-qa

Investigate an email address — MX and syntactic validation, Gravatar lookup, corporate email-format inference, breach exposure, and full mail-header analysis covering the Received chain, Message-ID and SPF, DKIM and DMARC results. Use for email OSINT, verifying whether an address exists, finding accounts registered to it, guessing a company's email format, or tracing where a suspicious message actually came from. Applies to business email compromise and invoice-fraud investigation, phishing triage, vendor-payment verification, and pre-engagement research. Reference at useosint.com/skills/what-an-email-reveals.

useosint avataruseosint
获取
pattern-of-life-from-socials

pattern-of-life-from-socials

21writing-content

Deep-dive a subject's social media presence — profile metadata, follower and mutual network, content analysis, and posting-time pattern of life across Instagram, Facebook, X/Twitter, TikTok, LinkedIn, Reddit, Telegram and Discord. Use when profiling a social account, mapping someone's associates, inferring a subject's timezone or routine from their posts, or archiving a profile before it is deleted. Applies to threat assessment and executive protection, insider-threat investigation, pre-litigation research, and personal exposure audits — with explicit limits on profiling uninvolved third parties. Reference at useosint.com/skills/pattern-of-life-from-socials.

useosint avataruseosint
获取
find-hidden-subdomains

find-hidden-subdomains

21devops-cloud

Enumerate an organisation's subdomains and sibling domains from Certificate Transparency logs and passive DNS, without sending traffic to the target. Covers crt.sh and CT log queries, certificate SAN fields, subfinder and amass, and newly issued TLS certificates. Use when looking for staging, dev, admin or VPN hosts, mapping the full hostname footprint of a domain, or spotting infrastructure a company forgot it had. Applies to attack-surface mapping, vendor and supply-chain security review, brand-infringement discovery, and M&A technical diligence. Reference at useosint.com/skills/find-hidden-subdomains.

useosint avataruseosint
获取
investigate-anything

investigate-anything

21agent-workflows

Start-here router and tradecraft baseline for any investigation into a person, company, domain, image or selector. Sets authorised scope, turns a vague request into an answerable intelligence question, writes a collection plan, picks the right workflow for the starting selector, and applies source grading and competing-hypothesis discipline. Use for "investigate this person or company", "do OSINT on X", "where do I start", or any open-source intelligence, due diligence, background or attribution task. Applies across due diligence, fraud, threat intelligence, journalism and compliance. Reference at useosint.com/skills/investigate-anything.

useosint avataruseosint
获取
who-really-owns-it

who-really-owns-it

21research-knowledge

Research companies, directors, shareholders and ultimate beneficial ownership in official corporate registries, filings and offshore datasets — OpenCorporates, UK Companies House and the PSC register, SEC EDGAR, US Secretary of State registries, EU business registers, GLEIF LEI records, OpenOwnership, OpenSanctions and the ICIJ Offshore Leaks database. Use when asked who owns or controls a company, to find a person's other directorships, or to unpick a group structure. Applies to KYB and UBO verification, AML and sanctions screening, nominee and shell-company detection, procurement integrity, and M&A diligence. Reference at useosint.com/skills/who-really-owns-it.

useosint avataruseosint
获取
where-was-this-taken

where-was-this-taken

21research-knowledge

End-to-end workflow to establish where and when a photo or video was captured and whether it is authentic — evidentiary handling, metadata extraction, reverse image search for provenance, visual geolocation, chronolocation from shadows, and manipulation checks, ending in a location finding with a stated confidence radius. Use when asked to verify where an image was taken, confirm or refute a claimed location or date, or authenticate media before relying on it. Applies to insurance claims, litigation evidence, disinformation analysis, and conflict and human-rights documentation. Reference at useosint.com/skills/where-was-this-taken.

useosint avataruseosint
获取
find-leaks-in-the-wild

find-leaks-in-the-wild

21browser-web

Find leaked or mentioned selectors circulating in pastes, leak forums, Telegram channels and dump markets, and judge whether a claimed leak is genuine or a recycled combolist. Covers paste aggregators, site: searches over paste hosts, channel indexes and leak-search services. Use when checking whether a name, email, domain or credential is circulating, verifying a breach claim made against your organisation, or setting up ongoing leak monitoring. Applies to incident response and breach triage, threat intelligence, brand and executive protection, and extortion-claim validation. Reference at useosint.com/skills/find-leaks-in-the-wild.

useosint avataruseosint
获取
google-like-a-spy

google-like-a-spy

21browser-web

Craft advanced search-engine queries and Google dorks to surface hidden files, documents and mentions. Covers site:, filetype:, inurl:, intitle:, intext: and before:/after: operators, verbatim search, exposed directory listings, config files, backups and open S3 buckets, and the operator differences between Google, Bing, DuckDuckGo and Yandex. Use when building a Google dork, hunting a leaked document, or searching paste sites and document repositories for a name, email or selector. Applies to data-exposure audits, pre-engagement reconnaissance, competitive and regulatory research, and insider-leak investigation. Reference at useosint.com/skills/google-like-a-spy.

useosint avataruseosint
获取
huawei-cloud-obs-upload

huawei-cloud-obs-upload

19security

Upload local files or directories to Huawei Cloud OBS (Object Storage Service) buckets, list OBS buckets with capacity and object count, and schedule periodic uploads via crontab. Use this skill when the user wants to: (1) upload a local file or directory to an OBS bucket, (2) list OBS buckets and check their storage capacity and object count, (3) set up a scheduled/periodic upload task to automatically sync a local directory to an OBS bucket. Trigger: user mentions "OBS", "object storage", "bucket list", "bucket capacity", "upload to OBS", "upload file", "upload directory", "scheduled upload", "periodic upload", "sync to bucket", "对象存储", "桶列表", "桶容量", "上传文件", "上传目录", "定时上传", "OBS管理"

huaweicloud avatarhuaweicloud
获取
huawei-cloud-cci-instance-management

huawei-cloud-cci-instance-management

19security

Huawei Cloud CCI (Cloud Container Instance) full lifecycle management using hcloud CLI. Covers Namespace, Network, Deployment, StatefulSet, Pod creation/update/delete/status, EIPPool for public IP, logs and metrics. Two-step confirmation for all destructive operations (delete namespace cascades all resources under it). Use this skill when the user wants to operate CCI serverless containers via command line. Triggers: CCI, 云容器实例, serverless container, 容器实例, namespace, deployment, statefulset, pod, EIPPool, CCI负载, 无服务器容器, 创建容器实例, 删除容器实例, 容器状态, 容器日志

huaweicloud avatarhuaweicloud
获取
huawei-cloud-obs-stats

huawei-cloud-obs-stats

19security

Query Huawei Cloud OBS (Object Storage Service) statistics: list buckets with capacity and object counts, query extranet/intranet download traffic with month-over-month comparison, and query total requests with month-over-month comparison. Use this skill when the user wants to: (1) list OBS buckets and check their storage capacity and object count, (2) query download traffic with MoM comparison, (3) query request counts with MoM comparison. Trigger: user mentions "OBS", "object storage", "bucket list", "bucket capacity", "download traffic", "total requests", "request count", "month-over-month", "OBS stats", "OBS management", "对象存储", "桶列表", "桶容量", "下载流量", "请求总数", "月环比", "OBS监控"

huaweicloud avatarhuaweicloud
获取
stream

stream

18security

Stream router for Chat, Video, Feeds, and Moderation. Use when the user wants to build a new app with Stream, scaffold a project, add Chat/Video/Feeds/Moderation to an existing app, integrate Stream, audit or migrate an integration, build for Swift/SwiftUI/UIKit/iOS/Xcode/Android/Kotlin/React Native/Expo/Flutter, query Stream data, list channels, list calls, show flagged messages, find users, run getstream CLI commands, install the Stream CLI, set up Stream, configure moderation, search Stream SDK documentation, or look up Stream React/iOS/Android/Node/Flutter/Unity SDK methods. Routes to the right sub-skill based on the task.

getstream avatargetstream
获取
dig-through-data-brokers

dig-through-data-brokers

16research-knowledge

Use people-search aggregators and primary public records to find addresses, phone numbers, relatives, age and background on a person, and to audit and remove your own exposure. Covers Spokeo, BeenVerified, Whitepages, TruePeopleSearch, FastPeopleSearch, That'sThem, Radaris, Intelius and Pipl, plus voter files and county court and property records. Use when running a people search or reverse address lookup, tracing a debtor or missing person, building a subject's address history, or removing yourself from broker sites. Applies to skip tracing and debt recovery, asset investigation, executive protection, and personal exposure audits. Explains the FCRA limits that bar broker data from employment, tenancy, insurance and credit decisions, and the GDPR position. Reference at useosint.com/skills/dig-through-data-brokers.

useosint avataruseosint
获取
who-owns-this-domain

who-owns-this-domain

16security

Establish who registered and who operates a domain using WHOIS, RDAP and DNS. Use when running a whois lookup, querying RDAP, digging A, AAAA, MX, NS, TXT, SOA or CAA records, reading SPF includes, DKIM selectors or DMARC rua addresses, finding the registrar, registrant or nameservers, doing reverse DNS, PTR, ASN or netblock lookups, or hunting historical WHOIS and passive DNS. Applies to phishing and brand-abuse takedown, domain-dispute and UDRP evidence, vendor verification before payment, and infrastructure attribution. Reference at useosint.com/skills/who-owns-this-domain.

useosint avataruseosint
获取
secrets-in-git-history

secrets-in-git-history

16security

Mine GitHub, GitLab and git history for identities, infrastructure and leaked credentials using commit author emails, GitHub code search, the commit .patch endpoint, trufflehog, gitleaks, git log pickaxe and full-ref history scans. Use when investigating a developer or organisation on GitHub, finding leaked API keys, AWS keys or tokens in code, enumerating org members and their personal repos, or recovering secrets deleted from HEAD but still present in history or forks. Applies to software supply-chain risk, credential exposure response, M&A technical diligence, and insider-threat investigation. Reference at useosint.com/skills/secrets-in-git-history.

useosint avataruseosint
获取
agent-fs

agent-fs

15security

Use when the user wants to store, retrieve, search, or manage files in agent-fs — an agent-first filesystem backed by S3. Triggers on: "save this to agent-fs", "find that file", "store this document", "search agent-fs", "list my files", "show version history", "revert file", "set up agent-fs", "get a signed url", "share this file", "manage members", "invite user", "list members", "remove member", "update role", "reset api key", "rotate api key", "lost my api key", file persistence for agents, shared agent filesystem, or any mention of the agent-fs CLI. Also use when the user needs to manage drives, manage org/drive members, generate presigned URLs, check recent activity, or use semantic search across stored files. Also use when the user wants to run SQL over stored data files ("query this csv", "sql over my files", "duckdb", "aggregate the parquet file", "query the sqlite db", "join these spreadsheets"). Also use when the user wants to mount or unmount agent-fs as a Linux FUSE filesystem ("mount agent-fs", "fuse mount", "fuse", "remote mount", "sandbox mount", "expose drives as files", "use cat/grep/mv on my agent-fs files", "umount the drive", "mount a remote drive", "mount from sprite", "mount from e2b", "mount from hetzner"). Also use when the user wants to use agent-fs as a just-bash filesystem. Also use when the user wants to set up agent-fs without Docker or S3 ("local filesystem backend", "filesystem storage", "no docker", "onboard --filesystem", "store files on disk"). If the user mentions agent-fs in any context, always consult this skill.

desplega-ai avatardesplega-ai
获取
x-ray-a-company

x-ray-a-company

14testing-qa

Corporate due-diligence workflow — resolve a brand or website to its registered legal entity, map group structure and beneficial ownership, profile officers and directors, enumerate the digital estate, and screen litigation, insolvency, procurement, sanctions, PEP and adverse media. Use when asked to check out, vet or research a company, verify a supplier or counterparty before signing or paying, or assess whether a business is real. Applies to vendor and third-party risk, KYC and KYB onboarding, M&A and investor diligence, procurement integrity, and shell-company assessment. Reference at useosint.com/skills/x-ray-a-company.

useosint avataruseosint
获取
read-deleted-pages

read-deleted-pages

14browser-web

Recover deleted, edited or historical web content using the Wayback Machine and its CDX API, archive.today, Common Crawl and Memento/Timetravel. Use when a page is deleted, changed or 404s, checking what a site used to say, finding old team or staff pages, prior pricing, removed posts, pre-redaction wording or old contact details, enumerating every archived URL for a domain, or preserving evidence before it disappears. Applies to litigation and evidence preservation, regulatory and disclosure review, due diligence on a company's history, and journalism. Reference at useosint.com/skills/read-deleted-pages.

useosint avataruseosint
获取
find-exposed-servers

find-exposed-servers

14devops-cloud

Find internet-exposed hosts, ports, services and devices using third-party internet-scan data instead of touching the target. Covers Shodan and Censys query syntax, service banners, favicon-hash and TLS-certificate pivots, origin-IP discovery behind Cloudflare or a CDN, and exposed databases, dashboards, cameras and ICS devices. Use when asked what a company has exposed to the internet, to check open ports on an IP or netblock, or to write a Shodan filter query. Applies to external attack-surface management, third-party and vendor security review, M&A technical diligence, and pre-engagement reconnaissance. Reference at useosint.com/skills/find-exposed-servers.

useosint avataruseosint
获取
fish-audio

fish-audio

13security

Generate AI text-to-speech audio with Fish Audio and browse public reference voices via AceDataCloud API. Use when creating voiceover/narration audio (TTS), synthesizing multilingual speech, or selecting a Fish reference voice from the model catalog.

acedatacloud avataracedatacloud
获取
emblem-ai-agent-wallet

emblem-ai-agent-wallet

12security

Connect to EmblemVault and manage wallet-aware workflows via EmblemAI with review-first, operator-controlled actions. Supports Solana, Ethereum, Base, BSC, Polygon, Hedera, and Bitcoin. Also use when the user needs Emblem's auth model explained: one browser auth flow can log a user in with wallets, email/password, or social sign-in, while agent mode can auto-provision a profile-scoped wallet with no manual setup.

emblemcompany avataremblemcompany
获取
openclaw-security-watchdog

openclaw-security-watchdog

12security

OpenClaw security scanning skill that performs comprehensive system security audits and generates human-friendly reports

reason-machines avatarreason-machines
获取
avast-premium-security-malware-detection

avast-premium-security-malware-detection

12security

Detect and analyze potential malware distribution repositories masquerading as legitimate security software

reason-machines avatarreason-machines
获取
vibe-security-skill

vibe-security-skill

11security

Agent skill that audits vibe-coded apps for common security vulnerabilities introduced by AI coding assistants

reason-machines avatarreason-machines
获取