安全

安全审查、认证、权限和风险检查

242 个 Skills 可用

Skills 列表

ce-code-review

ce-code-review

24Ksecurity

Structured code review for bugs, regressions, tests, and standards. Use before PRs or when asked for review; report-only by default, with explicit local apply available for user-directed fix workflows.

everyinc avatareveryinc
获取
gke-upgrades

gke-upgrades

16Ksecurity

Plans, executes, and validates Google Kubernetes Engine (GKE) cluster upgrades and maintenance operations for both Standard and Autopilot clusters. Produces upgrade plans, pre/post-upgrade checklists, maintenance runbooks with gcloud commands, release channel strategy, and troubleshooting guides. Handles node pool upgrade strategies (surge, blue-green), version compatibility, PDB management, and workload-specific concerns (stateful, GPU, operators). Use this skill whenever the user mentions GKE upgrades, Kubernetes version bumps, node pool maintenance, GKE patching, cluster version management, release channel selection, maintenance windows, surge upgrades, stuck upgrades, or any GKE lifecycle management task — even casual mentions like "we need to upgrade our clusters" or "plan our next GKE maintenance" or "our upgrade is stuck." Don't use for GKE cluster creation, application onboarding, general networking/routing setup, or security policy configurations (use gke-basics or relevant GKE skills instead).

google avatargoogle
获取
lark-shared

lark-shared

14Ksecurity

首次设置 lark-cli、运行 auth login、切换用户/应用身份(--as)、处理权限拒绝或作用域错误、需要更新 lark-cli,或在 JSON 输出中看到 _notice 时使用。

larksuite avatarlarksuite
获取
seo-images

seo-images

12Ksecurity

Image optimization analysis for SEO and performance. Checks alt text, file sizes, formats, responsive images, lazy loading, CLS prevention, image SERP rankings (via DataForSEO), and image file optimization (WebP/AVIF conversion, IPTC/XMP metadata injection). Use when user says "image optimization", "alt text", "image SEO", "image size", "image audit", "optimize images", "image metadata", "image SERP", "convert to webp", or "image file optimize".

agricidaniel avataragricidaniel
获取
seo-programmatic

seo-programmatic

12Ksecurity

Programmatic SEO planning and analysis for pages generated at scale from data sources. Covers template engines, URL patterns, internal linking automation, thin content safeguards, and index bloat prevention. Use when user says "programmatic SEO", "pages at scale", "dynamic pages", "template pages", "generated pages", or "data-driven SEO".

agricidaniel avataragricidaniel
获取
graphql-architect

graphql-architect

11Ksecurity

Use when designing GraphQL schemas, implementing Apollo Federation, or building real-time subscriptions. Invoke for schema design, resolvers with DataLoader, query optimization, federation directives.

jeffallan avatarjeffallan
获取
atlassian-mcp

atlassian-mcp

11Ksecurity

Integrates with Atlassian products to manage project tracking and documentation via MCP protocol. Use when querying Jira issues with JQL filters, creating and updating tickets with custom fields, searching or editing Confluence pages with CQL, managing sprints and backlogs, setting up MCP server authentication, syncing documentation, or debugging Atlassian API integrations.

jeffallan avatarjeffallan
获取
secure-code-guardian

secure-code-guardian

11Ksecurity

Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as hashing passwords with bcrypt/argon2, sanitizing SQL queries with parameterized statements, configuring CORS/CSP headers, validating input with Zod, and setting up JWT tokens. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention, secure session management, and security hardening. For pre-built OAuth/SSO integrations or standalone security audits, consider a more specialized skill.

jeffallan avatarjeffallan
获取
security-reviewer

security-reviewer

11Ksecurity

Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance. Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews, dependency audits, secrets scanning, or compliance checks. Produces vulnerability reports, prioritized recommendations, and compliance checklists.

jeffallan avatarjeffallan
获取
websocket-engineer

websocket-engineer

11Ksecurity

Use when building real-time communication systems with WebSockets or Socket.IO. Invoke for bidirectional messaging, horizontal scaling with Redis, presence tracking, room management.

jeffallan avatarjeffallan
获取
wordpress-pro

wordpress-pro

11Ksecurity

Develops custom WordPress themes and plugins, creates and registers Gutenberg blocks and block patterns, configures WooCommerce stores, implements WordPress REST API endpoints, applies security hardening (nonces, sanitization, escaping, capability checks), and optimizes performance through caching and query tuning. Use when building WordPress themes, writing plugins, customizing Gutenberg blocks, extending WooCommerce, working with ACF, using the WordPress REST API, applying hooks and filters, or improving WordPress performance and security.

jeffallan avatarjeffallan
获取
oauth

oauth

10Ksecurity

Configure OAuth providers (Google, Apple, Microsoft, Facebook, GitHub, etc.) to work with portless local dev URLs. Use when setting up OAuth redirect URIs, fixing "redirect_uri_mismatch" or "invalid redirect" errors, configuring sign-in providers for local development, or when a provider rejects .localhost subdomains. Triggers include "OAuth not working with portless", "redirect URI mismatch", "Google/Apple/Microsoft sign-in fails locally", "configure OAuth for local dev", or any task involving OAuth callback URLs with portless domains.

vercel-labs avatarvercel-labs
获取
capability-evolver

capability-evolver

8.9Ksecurity

A self-evolution engine for AI agents. Analyzes runtime history to identify improvements and applies protocol-constrained evolution. Communicates with EvoMap Hub via local Proxy mailbox.

autogame-17 avatarautogame-17
获取
dbs-goal

dbs-goal

7.9Ksecurity

dontbesilent 目标清晰化。用维特根斯坦的语言哲学把模糊的目标审计成可检查的交付物。 触发方式:/dbs-goal、/目标、「帮我搞清楚目标」「我想做个人 IP」「我的目标是成为...」「我想变得更...」 Goal clarification using Wittgenstein's philosophy of language. Audits fuzzy goals into checkable deliverables. Trigger: /dbs-goal, "help me clarify my goal", "I want to become...", "my goal is..."

dontbesilent2025 avatardontbesilent2025
获取
ads-create

ads-create

7.7Ksecurity

Create source-grounded paid-ad campaign concepts, messaging, copy, creative briefs, and production plans from a validated brand profile, campaign objective, platform requirements, and optional audit evidence. Triggers on: campaign brief, campaign concepts, create a campaign, ad concepts, ad copy, ad messaging, creative brief, headlines, descriptions.

agricidaniel avataragricidaniel
获取
ads-photoshoot

ads-photoshoot

7.7Ksecurity

Generate rights-cleared paid-ad product photography variants from an authorized source image and validated brand profile. Triggers on: product photo, product photography, virtual photoshoot, photoshoot, enhance product image, studio shot, lifestyle shot, lifestyle product image, floating product image, ingredient shot.

agricidaniel avataragricidaniel
获取
ads-audit

ads-audit

7.6Ksecurity

Run a source-grounded paid-advertising audit for one or more of Google, Meta, YouTube, LinkedIn, TikTok, Microsoft, Apple, Amazon, Reddit, Pinterest, Snapchat, and X. Use for full ad checks, account health reviews, paid-media diagnostics, partial audits after authentication or worker failure, missing-platform weighting, beta-feature eligibility and scoring, spend audits, tracking audits, or prioritized opportunities and risks.

agricidaniel avataragricidaniel
获取
ads-budget

ads-budget

7.6Ksecurity

Plan and review paid-media budgets, bidding, pacing, marginal return, forecasts, CPA, ROAS, MER, LTV:CAC, constraints, and allocation across supported platforms. Use for ad budget allocation, media budget, bidding strategy, scaling, spend pacing, budget forecast, ROAS target, or investment tradeoffs.

agricidaniel avataragricidaniel
获取
ads-creative

ads-creative

7.6Ksecurity

Audit paid-ad copy, images, video, hooks, concepts, format coverage, platform-native fit, message match, creative fatigue, accessibility, and policy across supported platforms. Use for creative audit, ad creative, creative fatigue, creative diversity, ad copy review, video review, image review, or production priorities.

agricidaniel avataragricidaniel
获取
health

health

6.6Ksecurity

Runs a budget-aware agent-assisted engineering health audit for instruction/config drift, hooks/MCP, verifier surfaces, and AI maintainability. Use when users ask in any language to audit Claude, Codex, Pi, agent instructions, MCP or hooks, verifier coverage, or AI-maintainability drift. Not for debugging application code or reviewing PRs.

tw93 avatartw93
获取
ljg-writes

ljg-writes

6.6Ksecurity

写作引擎。像手术刀剖开一个观点,一层层剥到底。1000-1500 字。

lijigang avatarlijigang
获取
bunjang-search

bunjang-search

6.5Ksecurity

번개장터 검색, 상세조회, 찜, 채팅, 대량 수집, AI TOON export를 bunjang-cli로 안내한다.

nomadamas avatarnomadamas
获取
improve

improve

6.5Ksecurity

以高级顾问身份调查任意代码库,生成按优先级排序、自包含的实现计划,供其他模型/代理执行。严格只读源代码——自身从不实现、修复或重构任何内容。当被要求审计代码库、寻找改进机会(缺陷、安全、性能、测试覆盖、技术债务、迁移、开发者体验)、建议功能或项目下一步方向(路线图、产品方向),或为另一个代理生成交接计划时使用。

shadcn avatarshadcn
获取
toss-securities

toss-securities

6.4Ksecurity

토스증권 조회형 질문을 공식 Open API(OAuth2)로 우선 처리하고, 공식 credentials가 없으면 tossinvest-cli의 tossctl을 fallback으로 써서 계좌, 보유주식, 시세/종목/시장정보, 주문조회를 안전한 read-only 흐름으로 조회한다.

nomadamas avatarnomadamas
获取