安全

安全审查、认证、权限和风险检查

608 个 Skills 可用

Skills 列表

vercel-optimize

vercel-optimize

28Ksecurity

用于对已部署项目(尤其是 Next.js、SvelteKit、Nuxt 以及部分 Astro 应用)进行 Vercel 成本与性能优化。先收集 Vercel 指标、用量、项目配置和代码扫描结果;仅调查有指标支持的候选方案;基于已验证的文件和版本感知的 Vercel/框架文档生成排序后的建议。触发场景:Vercel 账单降低、慢或昂贵的路由、缓存优化机会、函数调用次数、构建分钟数、快速数据传输、Core Web Vitals、Bot Management、Fluid compute 或成本分解请求。

vercel-labs avatarvercel-labs
获取
gws-admin-reports

gws-admin-reports

27Ksecurity

Google Workspace Admin SDK:审计日志和使用情况报告。

googleworkspace avatargoogleworkspace
获取
gws-shared

gws-shared

27Ksecurity

gws CLI:用于身份验证、全局标志和输出格式化的共享模式。

googleworkspace avatargoogleworkspace
获取
gws-keep

gws-keep

27Ksecurity

管理 Google Keep 笔记。

googleworkspace avatargoogleworkspace
获取
senior-security

senior-security

26Ksecurity

Use when the user asks for STRIDE threat modeling, DREAD risk scoring, data-flow-diagram threat analysis, or a quick secret scan — or when a security request needs routing to the right specialist skill (pen-testing, incident response, cloud posture, red team, AI security, threat hunting, secure code review). This skill owns threat modeling; everything else routes to a sibling.

alirezarezvani avataralirezarezvani
获取
ce-proof

ce-proof

24Ksecurity

在 Proof 中发布、读取、评论或编辑 Markdown。适用于生成 Proof 分享链接、分享规格文档/方案/草稿,或在规划流程中发布并交接文档;请勿用于校对(proofread)、数学证明(math)、证据(evidence)或概念验证(proof-of-concept)等含义。

everyinc avatareveryinc
获取
ce-simplify-code

ce-simplify-code

24Ksecurity

在保证行为不变的前提下,对最近修改的代码进行简化,提升其可读性、复用度、质量与运行效率。适用于代码整理与重构阶段;如果是排查 Bug,请使用 ce-debug。

everyinc avatareveryinc
获取
ce-code-review

ce-code-review

24Ksecurity

针对 Bug、回归问题、测试用例及代码规范的结构化代码审查工具。适合在提交 PR 前或被请求 Review 时使用;默认仅生成审查报告(不修改代码),但在用户引导的自动修复流程中,支持通过显式参数开启本地应用。

everyinc avatareveryinc
获取
zoom-cobrowse-sdk

zoom-cobrowse-sdk

24Ksecurity

Reference skill for Zoom Cobrowse SDK. Use after routing to a collaborative-support workflow when implementing browser co-browsing, annotation tools, privacy masking, remote assist, or PIN-based session sharing.

anthropics avataranthropics
获取
google-cloud-scc-query

google-cloud-scc-query

20Ksecurity

Queries and retrieves active security findings, external exposures, toxic combinations, vulnerabilities, threats, and sensitive data risks from Google Cloud Security Command Center. Use when retrieving details for a security finding by its name, validating finding scope (e.g., verifying findingClass is TOXIC_COMBINATION, VULNERABILITY, EXTERNAL_EXPOSURE, or THREAT), or fetching finding details for triage. Don't use to draft remediations, apply patches, or execute configurations.

google avatargoogle
获取
iam-helper-for-privileged-access-management

iam-helper-for-privileged-access-management

20Ksecurity

Manages the end-to-end lifecycle of on-demand, temporary access using Privileged Access Manager (PAM). Use when a user asks to create, read, update, or delete PAM entitlements, request temporary access, or approve/deny pending PAM grants. Do NOT use for permanent IAM policy bindings, troubleshooting IAM permission errors, or general Google Cloud resource provisioning.

google avatargoogle
获取
gcloud

gcloud

19Ksecurity

Provides safety-critical validation, guardrails, and data reduction for gcloud CLI operations across Google Cloud Platform (GCP) services and infrastructure. Use when planning, generating, constructing, proposing, describing, or executing any gcloud CLI commands - including when answering questions about gcloud syntax, or formatting flags. Don't use when writing Google Cloud client library code or raw REST/gRPC API requests.

google avatargoogle
获取
google-cloud-storage-basics

google-cloud-storage-basics

19Ksecurity

Stores, retrieves, and manages data as objects in Cloud Storage (Google Cloud Storage, or GCS) buckets. Use when you need to interact with Cloud Storage — create or configure buckets, upload, download, stream, or transfer data, organize objects with folders, generate signed URLs, control access (IAM, ACLs, public access prevention), set storage classes and tiering (Standard, Nearline, Coldline, Archive), manage cost and lifecycle, protect data (versioning, encryption/CMEK, retention and Bucket Lock, object holds, soft delete), host static websites, trigger Pub/Sub notifications on object changes, mount buckets as a file system (gcsfuse), or optimize storage performance at any scale. Covers the gcloud storage / gsutil CLI, JSON and XML APIs, client libraries, Terraform, and Cloud Storage MCP servers. Don't use for block storage (Persistent Disk), data warehousing/analytics (BigQuery), or databases (Cloud SQL, Spanner, Bigtable, Firestore).

google avatargoogle
获取
google-ads-api-quickstart

google-ads-api-quickstart

19Ksecurity

Guides developers through Google Ads API quickstart: credential setup, choosing from 6 client libraries/REST, configuring environments, and running a "retrieve campaigns" script. Troubleshoots common setup errors: USER_PERMISSION_DENIED, login_customer_id issues, and DEVELOPER_TOKEN_NOT_APPROVED. Use this skill when: - The user asks how to get started with the Google Ads API. - The user needs to set up Google Ads credentials or developer tokens. - The user wants to write a quickstart/example script for Google Ads. - The user encounters errors like USER_PERMISSION_DENIED or DEVELOPER_TOKEN_NOT_APPROVED.

google avatargoogle
获取
google-cloud-recipe-foundation-builder

google-cloud-recipe-foundation-builder

16Ksecurity

Deploys a baseline landing zone foundation for a Google Cloud Organization, establishing security guardrails using Organization Policies, resource hierarchy folders and projects, billing association, and centralized logging and monitoring. Deploys Google Cloud's recommended security controls and architecture. Use when setting up a new Google Cloud Organization or establishing a secure, enterprise-grade landing zone foundation. Don't use for individual project onboarding (use google-cloud-recipe-onboarding or product-specific skills instead).

google avatargoogle
获取
gke-upgrades

gke-upgrades

16Ksecurity

负责规划、执行和验证 Google Kubernetes Engine (GKE) 集群(包含 Standard 标准模式与 Autopilot 托管模式)的升级与运维操作。能够产出升级方案、升前/升后检查清单、附带 gcloud 命令的运维 Runbook、发布渠道(Release Channel)策略以及排障指南。支持各类节点池升级策略(如浪涌升级 surge、蓝绿升级 blue-green)、版本兼容性评估、PDB 规范管理,以及针对特定工作负载(有状态应用、GPU、Operator 算子)的专项处理。 当用户提及 GKE 升级、Kubernetes 版本跨度升级、节点池运维、GKE 打补丁、集群版本管理、发布渠道选择、维护时间窗口设定、浪涌升级、升级卡死或任何 GKE 生命周期的管理任务时(哪怕只是像“我们该升下集群了”、“规划一下下次 GKE 维护”或“升级卡住了”这类随口一提的描述),均可触发本 Skill。 请勿用于 GKE 集群新建、应用接入 (Onboarding)、基础网络/路由配置或安全策略配置(此类场景请使用 gke-basics 或其他相关的 GKE Skill)。

google avatargoogle
获取
zod-4

zod-4

15Kdevops-cloud

Zod 4 schema validation patterns. Trigger: When creating or updating Zod v4 schemas for validation/parsing (forms, request payloads, adapters), including v3 -> v4 migration patterns.

prowler-cloud avatarprowler-cloud
获取
lark-shared

lark-shared

14Ksecurity

首次设置lark-cli、运行auth login、切换用户/机器人身份(--as)、处理权限拒绝或scope错误、需要更新lark-cli、或在JSON输出中看到_notice时使用。

larksuite avatarlarksuite
获取
buddy-sings

buddy-sings

13Ksecurity

Use when user wants their Claude Code pet (/buddy) to sing a song. Triggers on any request that combines the concept of their Claude Code buddy, pet, or companion with singing or music. Supports multilingual triggers — match equivalent phrases in any language.

minimax-ai avatarminimax-ai
获取
maintain-greptile-rules

maintain-greptile-rules

13Ksecurity

Evaluate verified findings from merge-ready, Greptile, pull-request, CI, security, billing, and other code reviews, then promote durable review gaps into the version-controlled .greptile configuration. Use when a review uncovers a recurring or high-risk repository invariant that Greptile does not capture, when Greptile repeatedly produces a false positive, or when asked to audit or update OpenSEO's Greptile rules and context.

every-app avatarevery-app
获取
seo-images

seo-images

12Ksecurity

面向SEO和性能的图像优化分析。检查alt文本、文件大小、格式、响应式图片、懒加载、CLS预防、图片SERP排名(通过DataForSEO)以及图片文件优化(WebP/AVIF转换、IPTC/XMP元数据注入)。当用户提到“图片优化”、“alt文本”、“图片SEO”、“图片大小”、“图片审计”、“优化图片”、“图片元数据”、“图片SERP”、“转换为webp”或“图片文件优化”时使用。

agricidaniel avataragricidaniel
获取
seo-programmatic

seo-programmatic

12Ksecurity

适用于基于数据源批量生成页面的程序化 SEO(Programmatic SEO)规划与分析。涵盖模板引擎设计、URL 规则匹配、内链自动化、低质量薄内容(Thin Content)防护机制以及索引膨胀(Index Bloat)预防策略。当用户提到“programmatic SEO”、“程序化 SEO”、“批量生成页面”、“动态页面”、“模板页面”、“自动生成的页面”或“数据驱动 SEO”时使用。

agricidaniel avataragricidaniel
获取
graphql-architect

graphql-architect

11Ksecurity

用于设计 GraphQL schema、实现 Apollo Federation 或构建实时订阅。调用场景包括 schema 设计、使用 DataLoader 的解析器、查询优化、联邦指令。

jeffallan avatarjeffallan
获取
atlassian-mcp

atlassian-mcp

11Ksecurity

与Atlassian产品集成,通过MCP协议管理项目跟踪和文档。适用于使用JQL过滤器查询Jira问题、创建和更新自定义字段的工单、使用CQL搜索或编辑Confluence页面、管理冲刺和待办事项、设置MCP服务器认证、同步文档或调试Atlassian API集成。

jeffallan avatarjeffallan
获取