安全

安全审查、认证、权限和风险检查

599 个 Skills 可用

Skills 列表

ai-music

ai-music

2security

通过 `runcomfy` CLI 在 RunComfy 上生成 AI 音乐——一个智能路由,覆盖音乐模型目录。路由到 ElevenLabs AI 音乐生成(高级 44.1 kHz 立体声人声轨道,5 秒–5 分钟,$0.0083/秒)和 ACE Step / ACE Step 1.5(StepFun-AI 开放权重,标签驱动作曲,多语言歌词,$0.0002–0.0003/秒,约便宜 27 倍),以及 ACE Step 音频修补(在现有轨道内重新生成时间范围)和 ACE Step 音频外延(在轨道前后扩展)。根据用户的实际意图选择正确的模型——高级人声片段、廉价背景音乐库、多语言流行歌曲、修复糟糕的副歌、将 30 秒草稿延长为 2 分钟剪辑——并提供每个模型的文档化提示模式以及最小的 `runcomfy run` 调用。触发词包括“生成音乐”、“制作歌曲”、“AI 音乐”、“背景音乐”、“器乐轨道”、“配乐”、“广告曲”、“主题音乐”、“免版税音乐”、“作曲”、“带歌词的音乐”、“扩展音乐”、“修复这首歌”、“修补音乐”,或任何明确要求生成或编辑音乐的请求。

runcomfy-com avatarruncomfy-com
获取
ace-step

ace-step

2security

通过 `runcomfy` CLI 在 RunComfy 上使用 ACE Step 生成、修补和扩展音乐。ACE Step 是 StepFun-AI 的开源音乐基础模型——基于标签的作曲(流派、情绪、乐器)、支持多语言歌词和段落标记、5 秒到 4 分钟立体声输出、每秒 $0.0002–0.0003(比 ElevenLabs Music 便宜约 27 倍)。四个端点:ACE Step 文本转音频(默认)、ACE Step 1.5 文本转音频(50+ 语言歌词、改进的结构化歌词处理)、ACE Step 音频修补(在现有曲目内重新生成时间范围)、ACE Step 音频扩展(在现有曲目前后扩展)。触发词包括 "ace step"、"ace-step"、"acestep"、"ACE music"、"open music model"、"cheap AI music"、"inpaint audio"、"audio inpaint"、"extend music"、"audio outpaint"、"lengthen track"、"music with tags" 或任何明确要求使用 ACE Step 生成或编辑音乐的请求。

runcomfy-com avatarruncomfy-com
获取
find-the-original-image

find-the-original-image

2writing-content

Reverse image search across Yandex, Google Lens, Bing Visual Search, TinEye and Baidu to find where a picture came from and who published it first. Use when reverse image searching, identifying a photo, face, logo, product, uniform or building, tracing a profile picture or avatar, finding the oldest copy of an image, checking whether a photo is stock or a repost, or reverse-searching a video by keyframes. Applies to romance and investment scam investigation, fake-profile and synthetic-identity detection, disinformation and media verification, counterfeit and brand-infringement work, and insurance claim review. Reference at useosint.com/skills/find-the-original-image.

useosint avataruseosint
获取
is-this-photo-real

is-this-photo-real

2testing-qa

Verify whether an image or video is authentic, original and correctly captioned — provenance checks, error level analysis, noise and JPEG compression analysis, clone and copy-move detection, lighting and shadow consistency, C2PA Content Credentials, deepfake and AI-generation tells, and the honest limits of AI-detector tools. Use when fact-checking a photo or video, checking for a deepfake or AI-generated image, spotting manipulation, or testing whether footage is recycled or miscaptioned. Applies to KYC and onboarding fraud, insurance claim review, disinformation analysis, and evidence admissibility. Reference at useosint.com/skills/is-this-photo-real.

useosint avataruseosint
获取
what-leaked-about-you

what-leaked-about-you

2backend-api

Check and interpret data-breach exposure for an email, username, phone or name using Have I Been Pwned, the Pwned Passwords k-anonymity range API, DeHashed, IntelX and Snusbase. Use when checking breach or leak exposure, finding which services an account was registered with, interpreting a combolist or credential dump, assessing credential compromise, or auditing your own leaked personal data. Applies to incident response and account-takeover triage, executive and VIP protection, pre-employment and vendor risk screening, and personal privacy audits. Reference at useosint.com/skills/what-leaked-about-you.

useosint avataruseosint
获取
investigate-without-getting-made

investigate-without-getting-made

2security

Investigator OPSEC — threat-model who might notice you, control your attribution surface across IP, ASN, browser and TLS fingerprint, timing and logged-in accounts, separate research identity from real identity, build and age a sockpuppet research persona, and choose between VPN, residential proxy and Tor. Use when setting up a research account, avoiding tipping off a subject, worrying about LinkedIn profile-view leakage, needing a burner phone or email, or hardening a research VM or browser profile. Applies to covert due diligence, insider-threat investigation, source protection in journalism, and law-enforcement online work. Reference at useosint.com/skills/investigate-without-getting-made.

useosint avataruseosint
获取
limrun-xcode-bazel

limrun-xcode-bazel

1security

Build a Bazel-based iOS / macOS / Apple app on Limrun's remote build execution (RBE) instead of a local Mac, and install it on a remote iOS simulator. Use when the project is a Bazel workspace (MODULE.bazel / WORKSPACE) building rules_apple / rules_swift targets and the user wants to `bazel build` it or run it on a simulator, or when a `--config=limrun` build or install misbehaves. To then tap, type, screenshot, or otherwise interact with the running app, use limrun-ios-simulator. For non-Bazel (plain xcodebuild) projects use limrun-xcode instead.

limrun-inc avatarlimrun-inc
获取
bat-submit

bat-submit

1security

Submit an AI tool to BAT AI Tools (bataitools.com) via bat-cli CLI. Use a continuous 3-step workflow — extract, translate, then pack and submit.

bataitools avatarbataitools
获取
5dive-cli

5dive-cli

1security

Use the local `5dive` CLI on a 5dive runtime VM to spawn, inspect, send to, and tear down sibling agents — plus the shared task queue and org chart. Trigger when the user wants a worker, sub-agent, side task, parallel run, fan-out, or to delegate — or names a sibling agent ("ask X", "ping X", "tell X", "hand off to X", "coordinate with X"); confirm it exists via `5dive agent list --json`, then `agent send` / `agent ask`. Also for filing and tracking shared work (`5dive task add/ls/done`), the org chart (`5dive org tree`), parking a blocking question on a human (`task need`), and a quick recall of team memory (`5dive memory search`). For everything else the CLI can do — crew hosting, multi-account auth, auth recovery, declarative fleets/compose, goal DAGs, objectives, loops, compiling into the wiki, org-chart writes, governance votes, digest/usage/supervisor/fleet/diagnose, telegram pairing, the persona market, BYO providers, and the company wizard — see the `5dive-cli-extras` skill. When a request came over a chat channel (Telegram/Discord `<channel>` tag) and another agent should handle it, pass the chat context via `--reply-to-chat=<id> --reply-to-msg=<id>` so that agent replies from its own bot — don't relay. Always prefer `5dive` over running coding CLIs by hand.

5dive-ai avatar5dive-ai
获取
twitter-api

twitter-api

1security

A Twitter API alternative and X API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no OAuth and no developer application. Use when the user wants to search tweets by keyword, hashtag, or advanced operators (from:, to:, since:, until:, min_faves:, filter:), scrape a Twitter/X profile by handle, pull a user's tweets, replies, followers, or followings, fetch a single tweet with its replies or retweeters, read a Twitter List's members or tweets, check trending topics by country, or search for X accounts by name. Also covers Twitter data pipelines, competitor monitoring, hashtag tracking, sentiment analysis input, or follower export without the official X API's pricing tiers or app-review process.

fetcher-sh avatarfetcher-sh
获取
agentix-ceo

agentix-ceo

0security

管理你的团队——创建角色、分配任务、启动工作进程并监控进度

agentix-cloud avataragentix-cloud
获取
extension-authorization

extension-authorization

0security

授权系统,支持基于角色的访问控制。所有管理个人或受限数据的应用必备。

caffeinelabs avatarcaffeinelabs
获取
extension-oql

extension-oql

0security

使容器数据可被 Caffeine Data Intelligence 智能体查询。当应用存储结构化数据(Map/List/记录数组)且应能通过自然语言回答(如“顶级客户”、“按区域统计收入”、“活跃项目”)时使用。通过 `caffeineai-oql` mops 包的 `Expose` 混入,添加可发现的 `schema()` 和 JSON `execute()` 查询端点。

caffeinelabs avatarcaffeinelabs
获取
ai-music

ai-music

0security

Generate AI music on RunComfy via the `runcomfy` CLI — a smart router across the music-model catalog. Routes to ElevenLabs AI Music Generation (premium 44.1 kHz stereo vocal tracks, 5 s–5 min, $0.0083/s) and ACE Step / ACE Step 1.5 (StepFun-AI open-weights, tag-driven composition, multilingual lyrics, $0.0002–0.0003/s, ~27× cheaper), plus ACE Step audio-inpaint (regenerate a time range inside an existing track) and ACE Step audio-outpaint (extend a track before or after). Picks the right model for the user's actual intent — premium vocal hook, cheap background music library, multilingual pop song, repair a bad chorus, lengthen a 30 s draft into a 2 min cut — and ships each model's documented prompting patterns plus the minimal `runcomfy run` invoke. Triggers on "generate music", "make a song", "AI music", "background music", "instrumental track", "soundtrack", "jingle", "theme music", "royalty-free music", "compose", "music with lyrics", "extend music", "fix this song", "inpaint music", or any explicit ask to generate or edit music.

genmedia-labs avatargenmedia-labs
获取
x-api

x-api

0security

An X API alternative and Twitter API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no OAuth and no developer application. Use when the user wants to search X posts by keyword, hashtag, or advanced operators (from:, to:, since:, until:, min_faves:, filter:), scrape an X/Twitter profile by handle, pull a user's posts, replies, followers, or followings, fetch a single post with its replies or reposters, read an X List's members or posts, check trending topics by country, or search for X accounts by name. Also covers building an X data pipeline, social listening, competitor monitoring, hashtag tracking, or follower export without the official X API's pricing tiers or app-review process.

fetcher-sh avatarfetcher-sh
获取
imap-smtp-email

imap-smtp-email

0security

Read and send email via IMAP/SMTP. Check for new/unread messages, fetch content, search mailboxes, mark as read/unread, and send emails with attachments. Works with any IMAP/SMTP server including Gmail, Outlook, 163.com, vip.163.com, 126.com, vip.126.com, 188.com, and vip.188.com.

boomsystel-code avatarboomsystel-code
获取
incidentio-cli

incidentio-cli

0security

Invoke the `incidentio` CLI to drive the incident.io API — incidents, actions, follow-ups, alerts/alert sources/routes, escalations & on-call schedules, catalog (types/entries/resources), custom fields, severities, incident types/roles/statuses/timestamps, status pages (including creating and managing public pages, components, layout, subscribers, templates), workflows, users, teams, API keys, heartbeats, maintenance windows, and settings. Uses the public Bearer API (OpenAPI-generated commands) plus internal dashboard (cookie) commands generated from captured HARs, hand-curated internal endpoints, and a `raw` escape hatch for any un-codified path. Use whenever a task needs incident.io data or actions, such as "list our incidents", "create an incident", "show the on-call schedule", "build or manage a status page", "list status page subscribers", "tune a dashboard setting", or "hit an internal dashboard endpoint".

paymog avatarpaymog
获取
alan-review-pr

alan-review-pr

0security

Review a GitHub pull request using Alan's GitHub MCP tools

supatest-ai avatarsupatest-ai
获取
instagram-scraper

instagram-scraper

0security

Scrape public Instagram data without logging in and without a Meta developer account — profiles, posts, reels, stories, comments, hashtags, locations, and mentions. Use when the user wants to fetch an Instagram profile's follower count, bio, or post count, pull a profile's recent posts or reels, read the comments on a post, find posts under a hashtag or at a location, search for accounts by keyword, track a competitor's Instagram content, vet or discover influencers, export engagement metrics, monitor a brand's mentions, or build an Instagram data pipeline. Runs on Apify's Instagram Scraper; needs a free Apify account (API token), which this skill will help set up on first use.

skillify-sh avatarskillify-sh
获取
instagram-scraper

instagram-scraper

0security

Scrape public Instagram data without logging in and without a Meta developer account — profiles, posts, reels, stories, comments, hashtags, locations, and mentions. Use when the user wants to fetch an Instagram profile's follower count, bio, or post count, pull a profile's recent posts or reels, read the comments on a post, find posts under a hashtag or at a location, search for accounts by keyword, track a competitor's Instagram content, vet or discover influencers, export engagement metrics, monitor a brand's mentions, or build an Instagram data pipeline. Runs on Apify's Instagram Scraper; needs a free Apify account (API token), which this skill will help set up on first use.

jeniok avatarjeniok
获取
acomo

acomo

0security

プラットフォーム利用者(acomo 上でワークフローモデルを使って開発する開発者)向け。 acomo CLI および公開 API の標準的な使い方(モデル取得・プロセス操作・認証)を案内する。 acomo 本体の内部実装は対象外。 acomo CLI を使うとき、ワークフローやプロセスの操作・モデル定義の確認を行うときに参照する。

progress-all avatarprogress-all
获取
safe-action-middleware

safe-action-middleware

0security

Use when implementing middleware for next-safe-action -- authentication, authorization, logging, rate limiting, error interception, context extension, or creating standalone reusable middleware with createMiddleware() or createValidatedMiddleware(). Covers both use() (pre-validation) and useValidated() (post-validation) middleware.

next-safe-action avatarnext-safe-action
获取
gws-shared

gws-shared

0security

gws CLI: Shared patterns for authentication, global flags, and output formatting.

streakyc avatarstreakyc
获取