安全
安全审查、认证、权限和风险检查
Skills 列表

returns-reverse-logistics
汇总并代码化的专业经验,涵盖退货授权、收货与质检分级、处置决策(Restock/清仓/报废等)、退款处理、退货欺诈识别及质保理赔管理。由拥有 15 年以上实战经验的退货运营专家整理提炼。包含商品定级标准、处置经济学模型、欺诈模式识别和供应商追偿(RTV)流程。适用于处理商品退货、逆向物流、退款决策、退货欺诈风控或质保理赔等场景。
affaan-m
x-api
X/Twitter API 集成,用于发布推文、帖子、阅读时间线、搜索和分析。涵盖 OAuth 认证模式、速率限制和平台原生内容发布。当用户希望以编程方式与 X 交互时使用。
affaan-m
enterprise-agent-ops
通过可观测性、安全边界和生命周期管理来运行长期存在的智能体工作负载。
affaan-m
laravel-security
Laravel 安全最佳实践 — 包含身份验证、权限授权、Eloquent 操作安全、CSRF 与 XSS 防御、API 安全以及生产环境安全部署配置。
affaan-m
django-security
Django 安全最佳实践,涵盖身份验证、授权、CSRF 保护、SQL 注入防护、XSS 防护以及安全部署配置。
affaan-m
springboot-security
Spring Security 在 Java Spring Boot 服务中用于身份验证/授权、验证、CSRF、密钥、标头、速率限制和依赖安全的最佳实践。
affaan-m
security-review
在添加身份验证、处理用户输入、使用密钥、创建API端点或实现支付/敏感功能时使用此技能。提供全面的安全检查清单和模式。
affaan-m
caveman-setup
Wire the current repository through the Caveman Cloud gateway so every LLM request is measured — cost, tokens, latency — with zero behavior change. Use when the user pastes the Caveman setup prompt, says "set up caveman", or wants LLM spend observability added to an app. Requires the gateway URL and a Cave API key (the setup prompt carries both).
juliusbrussee
security-and-hardening
强化代码以抵御漏洞。适用于处理用户输入、身份验证、数据存储或外部集成时。适用于构建任何接受不可信数据、管理用户会话或与第三方服务交互的功能。
addyosmani
code-review-and-quality
执行多维度代码审查。在合并任何变更之前使用。在审查自己、其他智能体或人类编写的代码时使用。当需要在代码进入主分支之前从多个维度评估代码质量时使用。
addyosmani
paperclip
调用 Paperclip 控制面 API 进行任务协调与治理。适用于查看任务分派、更新 issue 状态、发表评论、委派工作、管理 Routine,或调用 Paperclip API 端点。
paperclipai
agent-security-manager
Agent skill for security-manager - invoke with $agent-security-manager
ruvnet
agent-v3-security-architect
Agent skill for v3-security-architect - invoke with $agent-v3-security-architect
ruvnet
agent-production-validator
Agent skill for production-validator - invoke with $agent-production-validator
ruvnet
claims
Claims-based authorization for agents and operations. Grant, revoke, and verify permissions for secure multi-agent coordination. Use when: permission management, access control, secure operations, authorization checks. Skip when: open access, no security requirements, single-agent local work.
ruvnet
agent-multi-repo-swarm
Agent skill for multi-repo-swarm - invoke with $agent-multi-repo-swarm
ruvnet
flow-nexus-platform
Comprehensive Flow Nexus platform management - authentication, sandboxes, app deployment, payments, and challenges
ruvnet
agent-specification
Agent skill for specification - invoke with $agent-specification
ruvnet
agent-code-review-swarm
Agent skill for code-review-swarm - invoke with $agent-code-review-swarm
ruvnet
agent-architecture
Agent skill for architecture - invoke with $agent-architecture
ruvnet
github-multi-repo
Multi-repository coordination, synchronization, and architecture management with AI swarm orchestration
ruvnet
security-audit
Comprehensive security scanning and vulnerability detection. Includes input validation, path traversal prevention, CVE detection, and secure coding pattern enforcement. Use when: authentication implementation, authorization logic, payment processing, user data handling, API endpoint creation, file upload handling, database queries, external API integration. Skip when: read-only operations on public data, internal development tooling, static documentation, styling changes.
ruvnet
release-openspec
Use this skill when releasing OpenSpec: audit merged work and changeset coverage, decide whether a catch-up changeset PR is needed, prepare or resume the Changesets Version Packages PR, cut a beta or stable release, verify publishing, and polish GitHub release notes. Also use when asked whether an open release PR is complete, what the next release step is, or to continue a release paused for human approval.
fission-ai
openspec-new-change
Start a new OpenSpec change using the experimental artifact workflow. Use when the user wants to create a new feature, fix, or modification with a structured step-by-step approach.
fission-ai