安全
安全审查、认证、权限和风险检查
Skills 列表

ai-music
通过 `runcomfy` CLI 在 RunComfy 上生成 AI 音乐——一个智能路由,覆盖音乐模型目录。路由到 ElevenLabs AI 音乐生成(高级 44.1 kHz 立体声人声轨道,5 秒–5 分钟,$0.0083/秒)和 ACE Step / ACE Step 1.5(StepFun-AI 开放权重,标签驱动作曲,多语言歌词,$0.0002–0.0003/秒,约便宜 27 倍),以及 ACE Step 音频修补(在现有轨道内重新生成时间范围)和 ACE Step 音频外延(在轨道前后扩展)。根据用户的实际意图选择正确的模型——高级人声片段、廉价背景音乐库、多语言流行歌曲、修复糟糕的副歌、将 30 秒草稿延长为 2 分钟剪辑——并提供每个模型的文档化提示模式以及最小的 `runcomfy run` 调用。触发词包括“生成音乐”、“制作歌曲”、“AI 音乐”、“背景音乐”、“器乐轨道”、“配乐”、“广告曲”、“主题音乐”、“免版税音乐”、“作曲”、“带歌词的音乐”、“扩展音乐”、“修复这首歌”、“修补音乐”,或任何明确要求生成或编辑音乐的请求。
runcomfy-com
ace-step
通过 `runcomfy` CLI 在 RunComfy 上使用 ACE Step 生成、修补和扩展音乐。ACE Step 是 StepFun-AI 的开源音乐基础模型——基于标签的作曲(流派、情绪、乐器)、支持多语言歌词和段落标记、5 秒到 4 分钟立体声输出、每秒 $0.0002–0.0003(比 ElevenLabs Music 便宜约 27 倍)。四个端点:ACE Step 文本转音频(默认)、ACE Step 1.5 文本转音频(50+ 语言歌词、改进的结构化歌词处理)、ACE Step 音频修补(在现有曲目内重新生成时间范围)、ACE Step 音频扩展(在现有曲目前后扩展)。触发词包括 "ace step"、"ace-step"、"acestep"、"ACE music"、"open music model"、"cheap AI music"、"inpaint audio"、"audio inpaint"、"extend music"、"audio outpaint"、"lengthen track"、"music with tags" 或任何明确要求使用 ACE Step 生成或编辑音乐的请求。
runcomfy-com
find-the-original-image
Reverse image search across Yandex, Google Lens, Bing Visual Search, TinEye and Baidu to find where a picture came from and who published it first. Use when reverse image searching, identifying a photo, face, logo, product, uniform or building, tracing a profile picture or avatar, finding the oldest copy of an image, checking whether a photo is stock or a repost, or reverse-searching a video by keyframes. Applies to romance and investment scam investigation, fake-profile and synthetic-identity detection, disinformation and media verification, counterfeit and brand-infringement work, and insurance claim review. Reference at useosint.com/skills/find-the-original-image.
useosint
is-this-photo-real
Verify whether an image or video is authentic, original and correctly captioned — provenance checks, error level analysis, noise and JPEG compression analysis, clone and copy-move detection, lighting and shadow consistency, C2PA Content Credentials, deepfake and AI-generation tells, and the honest limits of AI-detector tools. Use when fact-checking a photo or video, checking for a deepfake or AI-generated image, spotting manipulation, or testing whether footage is recycled or miscaptioned. Applies to KYC and onboarding fraud, insurance claim review, disinformation analysis, and evidence admissibility. Reference at useosint.com/skills/is-this-photo-real.
useosint
what-leaked-about-you
Check and interpret data-breach exposure for an email, username, phone or name using Have I Been Pwned, the Pwned Passwords k-anonymity range API, DeHashed, IntelX and Snusbase. Use when checking breach or leak exposure, finding which services an account was registered with, interpreting a combolist or credential dump, assessing credential compromise, or auditing your own leaked personal data. Applies to incident response and account-takeover triage, executive and VIP protection, pre-employment and vendor risk screening, and personal privacy audits. Reference at useosint.com/skills/what-leaked-about-you.
useosint
investigate-without-getting-made
Investigator OPSEC — threat-model who might notice you, control your attribution surface across IP, ASN, browser and TLS fingerprint, timing and logged-in accounts, separate research identity from real identity, build and age a sockpuppet research persona, and choose between VPN, residential proxy and Tor. Use when setting up a research account, avoiding tipping off a subject, worrying about LinkedIn profile-view leakage, needing a burner phone or email, or hardening a research VM or browser profile. Applies to covert due diligence, insider-threat investigation, source protection in journalism, and law-enforcement online work. Reference at useosint.com/skills/investigate-without-getting-made.
useosint
limrun-xcode-bazel
Build a Bazel-based iOS / macOS / Apple app on Limrun's remote build execution (RBE) instead of a local Mac, and install it on a remote iOS simulator. Use when the project is a Bazel workspace (MODULE.bazel / WORKSPACE) building rules_apple / rules_swift targets and the user wants to `bazel build` it or run it on a simulator, or when a `--config=limrun` build or install misbehaves. To then tap, type, screenshot, or otherwise interact with the running app, use limrun-ios-simulator. For non-Bazel (plain xcodebuild) projects use limrun-xcode instead.
limrun-inc
bat-submit
Submit an AI tool to BAT AI Tools (bataitools.com) via bat-cli CLI. Use a continuous 3-step workflow — extract, translate, then pack and submit.
bataitools
5dive-cli
Use the local `5dive` CLI on a 5dive runtime VM to spawn, inspect, send to, and tear down sibling agents — plus the shared task queue and org chart. Trigger when the user wants a worker, sub-agent, side task, parallel run, fan-out, or to delegate — or names a sibling agent ("ask X", "ping X", "tell X", "hand off to X", "coordinate with X"); confirm it exists via `5dive agent list --json`, then `agent send` / `agent ask`. Also for filing and tracking shared work (`5dive task add/ls/done`), the org chart (`5dive org tree`), parking a blocking question on a human (`task need`), and a quick recall of team memory (`5dive memory search`). For everything else the CLI can do — crew hosting, multi-account auth, auth recovery, declarative fleets/compose, goal DAGs, objectives, loops, compiling into the wiki, org-chart writes, governance votes, digest/usage/supervisor/fleet/diagnose, telegram pairing, the persona market, BYO providers, and the company wizard — see the `5dive-cli-extras` skill. When a request came over a chat channel (Telegram/Discord `<channel>` tag) and another agent should handle it, pass the chat context via `--reply-to-chat=<id> --reply-to-msg=<id>` so that agent replies from its own bot — don't relay. Always prefer `5dive` over running coding CLIs by hand.
5dive-ai
twitter-api
A Twitter API alternative and X API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no OAuth and no developer application. Use when the user wants to search tweets by keyword, hashtag, or advanced operators (from:, to:, since:, until:, min_faves:, filter:), scrape a Twitter/X profile by handle, pull a user's tweets, replies, followers, or followings, fetch a single tweet with its replies or retweeters, read a Twitter List's members or tweets, check trending topics by country, or search for X accounts by name. Also covers Twitter data pipelines, competitor monitoring, hashtag tracking, sentiment analysis input, or follower export without the official X API's pricing tiers or app-review process.
fetcher-sh
agentix-ceo
管理你的团队——创建角色、分配任务、启动工作进程并监控进度
agentix-cloud
extension-authorization
授权系统,支持基于角色的访问控制。所有管理个人或受限数据的应用必备。
caffeinelabs
extension-oql
使容器数据可被 Caffeine Data Intelligence 智能体查询。当应用存储结构化数据(Map/List/记录数组)且应能通过自然语言回答(如“顶级客户”、“按区域统计收入”、“活跃项目”)时使用。通过 `caffeineai-oql` mops 包的 `Expose` 混入,添加可发现的 `schema()` 和 JSON `execute()` 查询端点。
caffeinelabs
ai-music
Generate AI music on RunComfy via the `runcomfy` CLI — a smart router across the music-model catalog. Routes to ElevenLabs AI Music Generation (premium 44.1 kHz stereo vocal tracks, 5 s–5 min, $0.0083/s) and ACE Step / ACE Step 1.5 (StepFun-AI open-weights, tag-driven composition, multilingual lyrics, $0.0002–0.0003/s, ~27× cheaper), plus ACE Step audio-inpaint (regenerate a time range inside an existing track) and ACE Step audio-outpaint (extend a track before or after). Picks the right model for the user's actual intent — premium vocal hook, cheap background music library, multilingual pop song, repair a bad chorus, lengthen a 30 s draft into a 2 min cut — and ships each model's documented prompting patterns plus the minimal `runcomfy run` invoke. Triggers on "generate music", "make a song", "AI music", "background music", "instrumental track", "soundtrack", "jingle", "theme music", "royalty-free music", "compose", "music with lyrics", "extend music", "fix this song", "inpaint music", or any explicit ask to generate or edit music.
genmedia-labs
x-api
An X API alternative and Twitter API alternative on fetcher.sh — pay-per-call in USDC via x402, or prepaid credits with a Bearer key, no OAuth and no developer application. Use when the user wants to search X posts by keyword, hashtag, or advanced operators (from:, to:, since:, until:, min_faves:, filter:), scrape an X/Twitter profile by handle, pull a user's posts, replies, followers, or followings, fetch a single post with its replies or reposters, read an X List's members or posts, check trending topics by country, or search for X accounts by name. Also covers building an X data pipeline, social listening, competitor monitoring, hashtag tracking, or follower export without the official X API's pricing tiers or app-review process.
fetcher-sh
imap-smtp-email
Read and send email via IMAP/SMTP. Check for new/unread messages, fetch content, search mailboxes, mark as read/unread, and send emails with attachments. Works with any IMAP/SMTP server including Gmail, Outlook, 163.com, vip.163.com, 126.com, vip.126.com, 188.com, and vip.188.com.
boomsystel-code
incidentio-cli
Invoke the `incidentio` CLI to drive the incident.io API — incidents, actions, follow-ups, alerts/alert sources/routes, escalations & on-call schedules, catalog (types/entries/resources), custom fields, severities, incident types/roles/statuses/timestamps, status pages (including creating and managing public pages, components, layout, subscribers, templates), workflows, users, teams, API keys, heartbeats, maintenance windows, and settings. Uses the public Bearer API (OpenAPI-generated commands) plus internal dashboard (cookie) commands generated from captured HARs, hand-curated internal endpoints, and a `raw` escape hatch for any un-codified path. Use whenever a task needs incident.io data or actions, such as "list our incidents", "create an incident", "show the on-call schedule", "build or manage a status page", "list status page subscribers", "tune a dashboard setting", or "hit an internal dashboard endpoint".
paymog
alan-review-pr
Review a GitHub pull request using Alan's GitHub MCP tools
supatest-ai
instagram-scraper
Scrape public Instagram data without logging in and without a Meta developer account — profiles, posts, reels, stories, comments, hashtags, locations, and mentions. Use when the user wants to fetch an Instagram profile's follower count, bio, or post count, pull a profile's recent posts or reels, read the comments on a post, find posts under a hashtag or at a location, search for accounts by keyword, track a competitor's Instagram content, vet or discover influencers, export engagement metrics, monitor a brand's mentions, or build an Instagram data pipeline. Runs on Apify's Instagram Scraper; needs a free Apify account (API token), which this skill will help set up on first use.
skillify-sh
instagram-scraper
Scrape public Instagram data without logging in and without a Meta developer account — profiles, posts, reels, stories, comments, hashtags, locations, and mentions. Use when the user wants to fetch an Instagram profile's follower count, bio, or post count, pull a profile's recent posts or reels, read the comments on a post, find posts under a hashtag or at a location, search for accounts by keyword, track a competitor's Instagram content, vet or discover influencers, export engagement metrics, monitor a brand's mentions, or build an Instagram data pipeline. Runs on Apify's Instagram Scraper; needs a free Apify account (API token), which this skill will help set up on first use.
jeniok
acomo
プラットフォーム利用者(acomo 上でワークフローモデルを使って開発する開発者)向け。 acomo CLI および公開 API の標準的な使い方(モデル取得・プロセス操作・認証)を案内する。 acomo 本体の内部実装は対象外。 acomo CLI を使うとき、ワークフローやプロセスの操作・モデル定義の確認を行うときに参照する。
progress-all
safe-action-middleware
Use when implementing middleware for next-safe-action -- authentication, authorization, logging, rate limiting, error interception, context extension, or creating standalone reusable middleware with createMiddleware() or createValidatedMiddleware(). Covers both use() (pre-validation) and useValidated() (post-validation) middleware.
next-safe-action
gws-shared
gws CLI: Shared patterns for authentication, global flags, and output formatting.
streakyc