所有 Skills
找到 8442 个 Skills
Skills 列表

assess-react-native-migration
评估现有移动端产品是否以及如何迁移到 React Native。适用于审计一个或多个产品代码库的迁移就绪度(包括 iOS、Android 及其他客户端分布在不同目录或独立仓库的情况);选择 Brownfield(混合/渐进式)、Greenfield(全新重构)或基于 Checkpoint(关键验证点)的路线;定义具有代表性的试跑方案;以及在正式实施前制定基线与 ROI 决策。当缺少产品范围或关键事实依据时,不会一次性发问卷,而是每轮严格追问干系人一个关键问题。
callstackincubator
swift-concurrency
诊断 Swift 并发问题,将基于回调的代码重构为 async/await,并在处理任务、Actor、@MainActor、Sendable、数据竞争、线程安全或与并发相关的编译器和 linter 警告时指导 Swift 6 迁移。
avdlee
pi-delegate
Delegate a coding task to the Pi coding agent CLI (`pi`) as a background implementer, then review its diff and land it yourself. Use this whenever the user wants to delegate implementation work to Pi - phrasings like "have Pi implement X", "delegate this to pi", "run it through Pi", or "use pi to implement/fix/refactor" - or wants to run a queue of coding tasks through Pi while staying the reviewer. DO NOT USE for tasks small enough to do inline, or when the user wants the code written directly without delegating.
amelnagdy
mantis-reflect
Extracts learnings from execution trajectories at the end of a Mantis loop. Use to parse agent conversations, extract successes, failures, and false assumptions, and append them to workspace/learnings.jsonl. Don't use for analyzing source code or writing patches.
google
mantis-chain
Analyzes individual security findings to identify and construct complex exploit chains. Use after validation stages to see if multiple low-severity bugs can be combined into a higher impact vulnerability. Don't use for initial codebase auditing or writing patch code.
google
mantis-meta-agent
Acts as the persistent supervisor, launching and monitoring the automated review campaign. Use when running a long-running, continuous security review campaign that needs autonomous coordination. Don't use for executing individual review stages directly.
google
mantis-structural-index
Builds a content-addressed semantic-unit index from source code for structural context. Use when a pinned or live codebase is available and structural cross-reference data would improve research quality. Don't use for findings analysis, patching, or reporting.
google
nosql-injection
NoSQL 注入手册。当目标系统存在 MongoDB 风格的运算符、JSON 查询对象、灵活的搜索过滤器或后端查询 DSL,且可能导致数据或逻辑被滥用时使用。
yaklang
validate-skills
验证此仓库中的技能是否符合 agentskills.io 规范和 Claude Code 最佳实践。通过 /validate-skills 命令使用。
callstackincubator
github-actions
React Native iOS 模拟器与 Android 模拟器云端构建的 GitHub Actions 工作流范式,支持生成可下载的构建产物。适用于搭建 CI 构建流水线,或通过 gh CLI / GitHub API 下载 GitHub Actions 构建产物。
callstackincubator
huashu-md-to-pdf
将 Markdown 文档转换为专业的 PDF 白皮书,采用苹果设计风格。 支持完整的 Markdown 语法(代码块、表格、引用、列表等)。 自动生成封面、目录、页眉页脚。 使用场景:技术文档、白皮书、教程、报告等需要专业排版的 Markdown 文档。
alchaincyf
github
使用 gh CLI 进行 GitHub 操作的模式,涵盖拉取请求、堆叠 PR、代码审查、分支策略和仓库自动化。适用于处理 GitHub PR、合并策略或仓库管理任务。
callstackincubator
type-juggling
PHP 类型隐式转换(Type Juggling)与弱类型比较(`==`)绕过技巧。适用于身份验证、HMAC/签名校验或 Token 验证中使用了松散相等判断、强制数值转换或缺乏严格类型的哈希比较场景 —— 常见于旧版 PHP 代码及 CTF 风格的代码路径中。
yaklang
xslt-injection
XSLT 注入测试:解析器指纹识别、XXE 与 document() SSRF、EXSLT 文件写入原语,以及 PHP/Java/.NET 扩展 RCE 攻击面。当目标存在用户可控的 XSLT/样式表输入或转换接口时使用。
yaklang
upgrading-react-native
通过应用 rn-diff-purge 模板 diff、更新 package.json 依赖、迁移 iOS 及 Android 原生配置、处理 CocoaPods 和 Gradle 变更,以及应对 Breaking Change(破坏性 API 更新),将 React Native 应用平滑升级到更高版本。适用于升级 React Native、提升 RN 版本、从 RN 0.x 跨版本升级到 0.y,或在升级 React Native 时同步迁移 Expo SDK 等场景。
callstackincubator
context-engineering
Understand the components, mechanics, and constraints of context in agent systems. Use when writing, editing, or optimizing commands, skills, or sub-agents prompts.
neolabhq
thought-based-reasoning
Use when tackling complex reasoning tasks requiring step-by-step logic, multi-step arithmetic, commonsense reasoning, symbolic manipulation, or problems where simple prompting fails - provides comprehensive guide to Chain-of-Thought and related prompting techniques (Zero-shot CoT, Self-Consistency, Tree of Thoughts, Least-to-Most, ReAct, PAL, Reflexion) with templates, decision matrices, and research-backed patterns
neolabhq
http-parameter-pollution
HTTP 参数污染(HPP):当 query 或 body 中出现重复 key 时,服务器、代理、WAF 和应用框架的解析方式各不相同。当过滤层与应用层对“哪个值优先生效”存在分歧时使用此 Skill,可用于绕过防御、SSRF 二次 URL 注入、业务逻辑滥用或 CSRF token 混淆。
yaklang
open-redirect
开放重定向(Open Redirect)攻击与利用手册。当 URL 参数、表单提交目标或 JavaScript Sink 节点控制了页面跳转地址,并可能将用户重定向至攻击者控制的目标时使用。
yaklang
race-condition
Web 应用的竞态条件(Race Condition)与 TOCTOU 漏洞测试指南。适用于测试一次性操作、高并发 HTTP 滥用、突破频率限制(Rate-limit bypass)、Turbo Intruder 闸门控制(gates)、HTTP/2 单数据包攻击(single-packet attacks)以及 CWE-362 类型的同步漏洞。
yaklang
dependency-confusion
通过包管理器依赖混淆(Dependency Confusion)开展供应链安全测试:当内部私有包名被解析到攻击者控制的公共注册表时,会导致恶意代码被安装并执行脚本。适用于 npm/pip/gem/Maven/Composer/Docker 等配置清单(manifest)审查及获授权的红队供应链演练。
yaklang
web-cache-deception
Web 缓存欺骗与缓存污染实战手册。适用于因路径混淆或缓存键(Cache Key)篡改,导致 CDN、反向代理或应用层缓存可能将已认证用户的敏感内容分发给其他用户的场景。
yaklang
csv-formula-injection
CSV / 电子表格公式注入(DDE、Excel/LibreOffice、Google Sheets IMPORT* 函数)。适用于导出、导入或用户自定义字段接入电子表格及报表工具的场景。
yaklang
clickjacking
点击劫持(Clickjacking)实战指南。适用于测试目标页面是否可被框架嵌套(framed)、X-Frame-Options 或 CSP frame-ancestors 是否正确配置,以及 UI 覆盖劫持攻击(UI redress)能否引发敏感操作。
yaklang