所有 Skills

找到 8442 个 Skills

Skills 列表

mantis-architecture

mantis-architecture

1.5Kdevops-cloud

Synthesizes raw learnings and codebase analysis into an interlinked Markdown Knowledge Base (KB). Use at the beginning of a loop to build or update architecture.md, entities, and vulnerabilities. Don't use for generating threat models or formulating execution plans.

google avatargoogle
获取
mantis-summarize

mantis-summarize

1.5Kprompting-reasoning

Pre-processes the repository by generating security-focused summaries (mantis-summary.md) for each directory to make planning and research more efficient. Use when starting a review campaign to map the codebase before threat modeling and planning. Don't use for executing code reviews, writing test scripts, or patching code.

google avatargoogle
获取
mantis-review

mantis-review

1.5Kprompting-reasoning

Independently reviews findings and filters out false positives. Use when consolidated findings need validation against the actual source code. Don't use for reproducing crashes or patching code.

google avatargoogle
获取
mantis-plan

mantis-plan

1.5Kbackend-api

Formulates a targeted defensive security reviewing plan based on the active threat model and historical learnings. Use when starting a security review campaign to map the codebase boundaries and generate a roadmap (workspace/plan.json). Don't use for executing code reviews, writing test scripts, or patching code.

google avatargoogle
获取
mantis-critic

mantis-critic

1.5Kprompting-reasoning

Assesses the production viability of findings, filtering out debug-only features and assertion traps. Use when findings have been validated and you need to confirm they are triggerable in production release builds (with assertions disabled). Don't use for writing reproduction scripts or patches.

google avatargoogle
获取
mantis-researcher

mantis-researcher

1.5Ksecurity

Audits production source code files based on the strategy in workspace/plan.json. Use when a review plan exists and you need to perform static analysis and deep-dive reviews of targeted files. Don't use for planning, deduplicating, or writing patches.

google avatargoogle
获取
mantis-report

mantis-report

1.5Kprompting-reasoning

Generates a human-readable security review packet compiled from confirmed findings and exploit chains. Use at the end of a review cycle to produce stakeholder-facing documentation. Don't use for auditing code or verifying patches directly.

google avatargoogle
获取
mantis-reproduce

mantis-reproduce

1.5Kdevops-cloud

Generates and runs crash reproducers to verify security flaws. Use when viable findings exist and you need to write and execute a script or payload to verify the crash. Don't use for code auditing or patching.

google avatargoogle
获取
mantis-dedupe

mantis-dedupe

1.5Kresearch-knowledge

Consolidates raw security findings to eliminate redundant reports. Use when raw findings have been generated by the researcher and need consolidation before review. Don't use for initial code auditing or patch generation.

google avatargoogle
获取
mantis-calibrate

mantis-calibrate

1.5Ksecurity

Calculates the final risk score based on empirical evidence and architectural impact. Use when findings have been fully processed by previous stages and you need to append final risk scores to the finding files. Don't use for discovering new vulnerabilities or writing patches.

google avatargoogle
获取
mantis-patch

mantis-patch

1.5Kprompting-reasoning

Generates minimal security fixes using transactional isolation (shadow directories or file backups), applies patches, and verifies them. Use when security findings are successfully reproduced and need patches applied and verified. Don't use for initial vulnerability research or reproduction payload generation.

google avatargoogle
获取
mantis-history

mantis-history

1.5Kdatabase

Analyzes the repository's version control system (VCS) history to extract past vulnerabilities, security fixes, and vulnerability patterns. Use as an initial pre-processing step to build a historical vulnerabilities database (workspace/historical_learnings.jsonl) that informs subsequent stages about past issues and fixes. Don't use for code reviews, writing test scripts, or patching code.

google avatargoogle
获取
karpathy-llm-wiki

karpathy-llm-wiki

1.5Kresearch-knowledge

用于构建或维护个人LLM驱动的知识库。触发条件:将来源摄入到wiki、查询wiki知识、检查wiki质量、'添加到wiki'、'关于...我知道什么',或任何提及'LLM wiki'或'Karpathy wiki'的内容。

astro-han avatarastro-han
获取
modern-web-guidance

modern-web-guidance

1.5Kfrontend

检索现代 Web 开发最佳实践的工具。强制要求:处理任何 HTML/CSS 和客户端 JS 任务时必须优先执行此工具。切勿跳过——Web API 迭代极其迅速,模型训练权重中包含过时模式。 出现以下情况立即触发: - UI 与布局:模态框 (Modals)、对话框 (Dialogs)、Popover 弹出层、毛玻璃效果 (Glassmorphism/backdrop-filters)、锚点定位 (Anchor positioning)、容器查询 (Container queries)、`:has()`、`:user-valid`。 - 滚动与动画:视图过渡 (View Transitions)、滚动驱动动画 (Scroll-driven animations)、滚动视差/渐显 (Scroll parallax/reveals)。 - 性能优化:核心 Web 指标 CWV(LCP、INP)、`content-visibility`、Fetch Priority(加载优先级)、图片优化。 - 系统与底层 API:本地文件系统访问、WebUSB、WebSockets 同步、WebAssembly 小部件。 - 框架相关:在 React、Vue、Angular 中适配布局与样式。 - 通用前端:表单、自动填充、高级输入框、自定义滚动条、现代组件状态等。 请勿在以下场景触发: - 后端开发:数据库 SQL、ORM、Express API 路由。 - 部署流水线:CI/CD 部署、Docker、Actions。 - 通用/本地工具:本地脚本(Python/Go 工具)、ESLint、Git。

googlechrome avatargooglechrome
获取
prompt-engineering

prompt-engineering

1.5Kprompting-reasoning

Use this skill when you writing commands, hooks, skills for Agent, or prompts for sub agents or any other LLM interaction, including optimizing prompts, improving LLM outputs, or designing production prompt templates.

neolabhq avatarneolabhq
获取
authbypass-authentication-flaws

authbypass-authentication-flaws

1.5Kbackend-api

身份验证绕过测试 Playbook。适用于评估登录流程、密码重置逻辑、账号找回、多因素身份验证(MFA)绕过、Token 可预测性、防暴力破解能力以及会话边界缺陷等场景。

yaklang avataryaklang
获取
idor-broken-object-authorization

idor-broken-object-authorization

1.5Kbackend-api

IDOR(越权访问/不安全的实体直接引用)与对象级权限失效(BOLA)渗透测试手册。适用于请求中暴露了对象标识符(ID)、租户边界、可写字段,或缺少对象级授权校验的测试场景。

yaklang avataryaklang
获取
recon-and-methodology

recon-and-methodology

1.5Kdevops-cloud

资产收集与渗透测试方法论手册。适用于对新目标进行资产梳理、接口/端点发现、技术栈指纹识别以及制定结构化的漏洞挖掘与测试计划。

yaklang avataryaklang
获取
ssrf-server-side-request-forgery

ssrf-server-side-request-forgery

1.5Kbackend-api

SSRF 实战手册。当服务端涉及 URL 拉取、域名解析、远程内容导入,或者可能被诱导访问内网、云厂商 Metadata 及二次协议时使用。

yaklang avataryaklang
获取
next-best-practices

next-best-practices

1.5Kfrontend

Next.js best practices - file conventions, RSC boundaries, data patterns, async APIs, metadata, error handling, route handlers, image/font optimization, bundling

vercel-labs avatarvercel-labs
获取
discover-azure-skills

discover-azure-skills

1.5Kbackend-api

Searches the Azure skills catalog and recommends installable agent skills by matching an Azure task to skill metadata and plugin installation guidance. WHEN: before starting any task that involves an Azure or Microsoft-cloud service, product, or data source, when no currently loaded skill or tool already covers it.

microsoft avatarmicrosoft
获取
smux

smux

1.5Kagent-workflows

控制 tmux 窗格并在 AI 代理之间通信。当用户提到 tmux 窗格、跨窗格通信、向其他代理发送消息、读取其他窗格、管理 tmux 会话或与 tmux 中运行的进程交互时,请使用此技能。包含用于代理间消息传递的 tmux-bridge CLI 和用于直接会话控制的原始 tmux 命令。

shawnpana avatarshawnpana
获取
mantis-threat-model

mantis-threat-model

1.5Kdevops-cloud

Synthesizes trust boundaries, attack surfaces, and attacker profiles into a living threat model. Use as Stage B of the Knowledge Base generation process, reading architecture and entity definitions from the KB. Don't use for analyzing source code or extracting raw learnings from JSONL files.

google avatargoogle
获取
react-native-best-practices

react-native-best-practices

1.5Kfrontend

提供 React Native 性能优化指南,涵盖 FPS、TTI、包体积、内存泄漏、重渲染和动画。适用于涉及 Hermes 优化、JS 线程阻塞、桥接开销、FlashList、原生模块或调试卡顿和丢帧的任务。

callstackincubator avatarcallstackincubator
获取
想按分类查看?试试 /category/writing-content.