安全
安全审查、认证、权限和风险检查
Skills 列表

authentication
Implement iOS authentication flows with AuthenticationServices and LocalAuthentication. Use when building Sign in with Apple, passkey/WebAuthn registration or sign-in with ASAuthorizationPlatformPublicKeyCredentialProvider, ASAuthorizationController credential state and revocation handling, ASWebAuthenticationSession OAuth or third-party login, Password AutoFill, identity-token server validation, or local biometric re-authentication with LAContext.
dpearson2699
push-notifications
在 iOS/macOS 应用中实现、审查或调试推送通知——本地通知、远程(APNs)通知、富通知、通知操作、静默推送以及通知服务/内容扩展。适用于使用 UNUserNotificationCenter、注册远程通知、处理通知负载、设置通知类别和操作、创建富通知内容或调试通知投递。也适用于在 Swift 应用中处理提醒、角标、声音、后台推送或用户通知权限。
dpearson2699
ios-networking
使用 async/await 和结构化并发,在 iOS/macOS 应用中构建、审查或改进基于 URLSession 的网络代码。适用于 REST API、文件下载、数据上传、WebSocket 连接、分页、重试逻辑、请求中间件、缓存、后台传输或网络可达性监控。也适用于处理 Swift 应用中的 HTTP 请求、API 客户端、网络错误处理或数据获取。
dpearson2699
vibe-security
审计代码库中 AI 编码助手在“氛围编码”应用中引入的常见安全漏洞。检查暴露的 API 密钥、失效的访问控制(Supabase RLS、Firebase 规则)、缺失的身份验证验证、客户端信任问题、不安全的支付流程等。当用户询问安全问题、想要代码审查、提到“氛围编码”,或者当您编写或审查涉及身份验证、支付、数据库访问、API 密钥、机密或用户数据的代码时,请使用此技能——即使他们未明确提及安全。当用户说“这安全吗?”、“检查我的代码”、“审计这个”、“审查漏洞”或“有人能黑这个吗?”时,也触发此技能。
raroque
skill-scanner
Scan agent skills for security issues. Use when asked to "scan a skill",
getsentry
gha-security-review
对GitHub Actions工作流进行安全审查,发现可利用的漏洞。当被要求“审查GitHub Actions”、“审计工作流”、“检查CI安全”、“GHA安全”、“工作流安全审查”,或审查.github/workflows/中的pwn请求、表达式注入、凭证窃取和供应链攻击时使用。专注于利用,提供具体的PoC场景。
getsentry
find-bugs
查找本地分支变更中的错误、安全漏洞和代码质量问题。当被要求审查变更、查找错误、进行安全审查或审计当前分支上的代码时使用。
getsentry
security-review
安全代码审查,用于发现漏洞。当被要求进行“安全审查”、“查找漏洞”、“检查安全问题”、“审计安全”、“OWASP审查”或审查代码中的注入、XSS、认证、授权、加密问题时使用。提供基于置信度的系统性审查报告。
getsentry
integration-connectivity-connected-app-configure
Salesforce Connected Apps and External Client Apps OAuth configuration with 120-point scoring. Use this skill to configure OAuth flows, JWT bearer auth, Connected Apps, and External Client Apps in Salesforce. TRIGGER when: user configures OAuth flows, JWT bearer auth, Connected Apps, ECAs, or touches .connectedApp-meta.xml / .eca-meta.xml files. DO NOT TRIGGER when: configuring Named Credentials for callouts (use integration-connectivity-generate), reviewing permission policies (use platform-metadata-deploy), or writing Apex token-handling code (use platform-apex-generate).
forcedotcom
experience-ui-bundle-deploy
MUST activate when the project contains a uiBundles/*/src/ directory and the task involves deploying, pushing to an org, or post-deploy org setup. Use this skill to deploy a UI bundle app to a Salesforce org and run the full ordered setup: org authentication, pre-deploy build, metadata deploy, permission-set assignment, role assignment, Experience Cloud self-registration, seed-data import, and GraphQL schema fetch plus codegen. Activate when a uiBundles/ project also has files like *.network-meta.xml, org-setup.config.json, a data-plan.json in the data/ dir, or sfdx-project.json and the user mentions deploying, pushing, org setup, or post-deploy tasks. DO NOT TRIGGER when: creating a new UI bundle project from scratch (use experience-ui-bundle-project-generate); styling or editing pages in an existing app without deploying (use experience-ui-bundle-frontend-generate); adding a specific feature such as auth, search, or file upload without deploying (use the matching experience-ui-bundle-*-generate skill).
forcedotcom
platform-agentsetup-categories-fetch
Fetch agentic setup prompt categories from a connected Salesforce org using the Connect API. Use this skill to call GET /agenticsetup/categories and return the list of prompt categories, optionally with their nested prompts. TRIGGER when: user asks to get, fetch, list, or show agentic setup categories, prompt categories, setup copilot categories, prompt library categories, available setup prompts, Agentforce prompt library, or copilot prompts. DO NOT TRIGGER when: user wants to create new categories, work with non-categories endpoints, or generate OpenAPI specs.
forcedotcom
dx-org-permission-set-assign
ALWAYS USE THIS SKILL to assign permission sets to org users. Assign one or more permission sets to org users using the sf org assign permset command. TRIGGER when the user asks to assign, grant, give, add, or apply permission sets to users, admins, specific orgs, or specific users. Supports granting permissions, giving access, and adding permission sets to default admin or specific users via --on-behalf-of. DO NOT TRIGGER for listing permission sets or checking user permissions.
forcedotcom
platform-sharing-rules-generate
当用户需要创建、编辑、删除或管理 Salesforce 共享规则元数据时,使用此技能。触发条件:用户提及共享规则、记录共享、基于条件的共享、基于角色的共享、访客用户共享、sharingRules、sharingCriteriaRules、sharingGuestRules、sharingOwnerRules、.sharingRules-meta.xml 文件,或要求与特定角色或组共享记录。当用户想要修改或删除现有共享规则,或更新共享规则条件或访问级别时,也触发。当用户需要权限集或配置文件(使用 platform-permission-set-generate),或需要对象级安全而非记录级共享(使用 platform-permission-set-generate)时,不要触发。
forcedotcom
verified-agent-identity
了解你的智能体(KYA)。基于Billions网络的去中心化身份系统,用于智能体。通过Billions ERC-8004和认证注册表将智能体与人类身份关联。验证并生成认证证明。基于iden3自主身份协议。
billionsnetwork
pwa-development
渐进式Web应用 - Service Worker、缓存策略、离线支持、Workbox
alinaqi
playwright-testing
使用 Playwright 进行端到端测试 - 页面对象、跨浏览器、CI/CD
alinaqi
android-kotlin
Android Kotlin development with Coroutines, Jetpack Compose, Hilt, and MockK testing
alinaqi
angular-routing
在 Angular v20+ 应用中实现路由,支持懒加载、函数式守卫、解析器和路由参数。用于导航设置、受保护路由、基于路由的数据加载和嵌套路由。触发条件包括路由配置、添加认证守卫、实现懒加载或使用信号读取路由参数。
analogjs
angular-http
使用 Angular v20+ 中的 resource()、httpResource() 和 HttpClient 实现 HTTP 数据获取。适用于 API 调用、基于信号的 data loading、请求/响应处理以及拦截器。触发场景包括数据获取、API 集成、加载状态、错误处理,或将基于 Observable 的 HTTP 模式转换为基于信号的模式。
analogjs
kibana-connectors
Create and manage Kibana connectors for Slack, PagerDuty, Jira, webhooks, and more via REST API or Terraform. Use when configuring third-party integrations or managing connectors as code.
elastic
elasticsearch-security-troubleshooting
Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues. Use when the user reports a security error.
elastic
kibana-audit
Enable and configure Kibana audit logging for saved object access, logins, and space operations. Use when setting up Kibana audit, filtering events, or correlating Kibana and ES audit logs.
elastic
elasticsearch-audit
Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.
elastic
elasticsearch-authz
Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP/SAML.
elastic