所有 Skills
找到 8842 个 Skills
Skills 列表

anti-reversing-techniques
理解软件分析过程中遇到的反逆向、混淆和保护技术。在分析恶意软件规避技术、为CTF挑战实现反调试保护、逆向加壳二进制文件或构建需要检测虚拟化环境的安全研究工具时,使用此技能。
wshobson
ghidra-reverse
Use for free/open reverse engineering with Ghidra (headless or GUI), including decompile, cross-refs, and optional Ghidra MCP workflows when IDA is unavailable.
zhaoxuya520
mobile-native
Make a web app feel native on a phone — the small CSS and meta-tag fixes that separate "a website in a browser" from something that feels installed. Covers sticky hover states, tap highlight flashes, the 100vh bug, inputs that zoom the page, laggy taps, pull-to-refresh hijacking scroll, content under the notch, long-press selecting button text, carousels that scroll the wrong way, mismatched status bars, and the rule that you test on real hardware. Use when a web app is being built for or reviewed on mobile, when something "works in Chrome but feels wrong on my phone", when building a PWA, a bottom sheet, a carousel, a full-screen layout, or any touch interaction. For motion itself use animate; for React Native use animate-expo.
emilkowalski
ruff-recursive-fix
Run Ruff checks with optional scope and rule overrides, apply safe and unsafe autofixes iteratively, review each change, and resolve remaining findings with targeted edits or user decisions.
github
azure-architecture-autopilot
Design Azure infrastructure using natural language, or analyze existing Azure resources to auto-generate architecture diagrams, refine them through conversation, and deploy with Bicep. When to use this skill: - "Create X on Azure", "Set up a RAG architecture" (new design) - "Analyze my current Azure infrastructure", "Draw a diagram for rg-xxx" (existing analysis) - "Foundry is slow", "I want to reduce costs", "Strengthen security" (natural language modification) - Azure resource deployment, Bicep template generation, IaC code generation - Microsoft Foundry, AI Search, OpenAI, Fabric, ADLS Gen2, Databricks, and all Azure services
github
architecture-patterns
实现经过验证的后端架构模式,包括整洁架构、六边形架构和领域驱动设计。在设计新微服务的整洁架构、重构单体应用以使用限界上下文、实现六边形或洋葱架构模式,或调试应用层之间的依赖循环时,使用此技能。
wshobson
javascript-testing-patterns
使用 Jest、Vitest 和 Testing Library 实现全面的测试策略,涵盖单元测试、集成测试和端到端测试,包括模拟、测试夹具和测试驱动开发。适用于编写 JavaScript/TypeScript 测试、搭建测试基础设施或实施 TDD/BDD 工作流。
wshobson
modern-javascript-patterns
掌握 ES6+ 特性,包括 async/await、解构、展开运算符、箭头函数、Promise、模块、迭代器、生成器以及函数式编程模式,编写简洁高效的 JavaScript 代码。适用于重构遗留代码、实现现代模式或优化 JavaScript 应用。
wshobson
deployment-pipeline-design
设计包含审批门控、安全检查与部署编排的多阶段CI/CD流水线。在设计零停机部署流水线、实施金丝雀发布策略、设置多环境晋升工作流或调试CI/CD中失败的部署门控时使用此技能。
wshobson
evaluation-methodology
PluginEval 质量方法论——维度、评分标准、统计方法和评分公式。当需要理解插件质量如何衡量、解读某个维度的低分、决定如何提高技能的触发准确性或编排适配性、为市场校准评分阈值,或向 Neon 等外部合作伙伴解释质量徽章时,使用此技能。
wshobson
gdpr-compliant
Apply GDPR-compliant engineering practices across your codebase. Use this skill whenever you are designing APIs, writing data models, building authentication flows, implementing logging, handling user data, writing retention/deletion jobs, designing cloud infrastructure, or reviewing pull requests for privacy compliance. Trigger this skill for any task involving personal data, user accounts, cookies, analytics, emails, audit logs, encryption, pseudonymization, anonymization, data exports, breach response, CI/CD pipelines that process real data, or any question framed as "is this GDPR-compliant?". Inspired by CNIL developer guidance and GDPR Articles 5, 25, 32, 33, 35.
github
python-testing-patterns
使用 pytest、fixture、mock 和测试驱动开发实现全面的测试策略。在编写 Python 测试、设置测试套件或实施测试最佳实践时使用。
wshobson
orca-per-workspace-env
用于配置、检查、调试或验证 Orca 的工作区独立环境 Recipe——即为每个工作区按需新建、用完即弃的独立运行时(支持云端沙盒、虚拟机或本地环境)。除了工作区生命周期脚本外,还涵盖了首次初始化的全流程(服务商前置条件、可复用的基础快照、编程 Agent 鉴权快照、凭据与状态管理)。适用于搭建工作区环境、修补 `orca.yaml` 中的 `environmentRecipes` 配置项、生成服务商生命周期脚本脚手架,以及排查并解决 `orca vm recipe doctor` 报错。
stablyai
gtm-enterprise-onboarding
Four-phase framework for onboarding enterprise customers from contract to value realization. Use when implementing new enterprise customers, preventing churn during onboarding, or solving the adoption cliff that kills deals post-go-live. Includes the Week 4 ghosting pattern.
github
dotnet-timezone
.NET timezone handling guidance for C# applications. Use when working with TimeZoneInfo, DateTimeOffset, NodaTime, UTC conversion, daylight saving time, scheduling across timezones, cross-platform Windows/IANA timezone IDs, or when a .NET user needs the timezone for a city, address, region, or country and copy-paste-ready C# code.
github
gtm-developer-ecosystem
Build and scale developer-led adoption through ecosystem programs. Use when deciding open vs curated ecosystems, building developer programs, scaling platform adoption, or designing student program pipelines.
github
gtm-operating-cadence
Design meeting rhythms, metric reporting, quarterly planning, and decision-making velocity for scaling companies. Use when decisions are slow, planning is broken, the company is growing but alignment is worse, or leadership meetings consume all time without producing decisions.
github
quality-playbook
Run a complete quality engineering audit on any codebase. Derives behavioral requirements from the code, generates spec-traced functional tests, runs a three-pass code review with regression tests, executes a multi-model spec audit (Council of Three), and produces a consolidated bug report with TDD-verified patches. Finds the 35% of real defects that structural code review alone cannot catch. Works with any language. Trigger on 'quality playbook', 'spec audit', 'Council of Three', 'fitness-to-purpose', or 'coverage theater'.
github
acquire-codebase-knowledge
Use this skill when the user explicitly asks to map, document, or onboard into an existing codebase. Trigger for prompts like "map this codebase", "document this architecture", "onboard me to this repo", or "create codebase docs". Do not trigger for routine feature implementation, bug fixes, or narrow code edits unless the user asks for repository-level discovery.
github
gtm-ai-gtm
Go-to-market strategy for AI products. Use when positioning AI products, handling "who is responsible when it breaks" objections, pricing variable-cost AI, choosing between copilot/agent/teammate framing, or selling autonomous tools into enterprises.
github
gtm-board-and-investor-communication
Board meeting preparation, investor updates, and executive communication. Use when preparing board decks, writing investor updates, handling bad news with the board, structuring QBRs, or building board-level metric discipline. Includes the "Three Things" narrative model, the 4-tier metric hierarchy, and the pre-brief pattern that prevents board surprises.
github
gtm-enterprise-account-planning
Strategic account planning and execution for enterprise deals. Use when planning complex sales cycles, managing multiple stakeholders, applying MEDDICC qualification, tracking deal health, or building mutual action plans. Includes the "stale MAP equals dead deal" pattern.
github
gtm-partnership-architecture
Build and scale partner ecosystems that drive revenue and platform adoption. Use when building partner programs from scratch, tiering partnerships, managing co-marketing, making build-vs-partner decisions, or structuring crawl-walk-run partner deployment.
github
semantic-kernel
Create, update, refactor, explain, or review Semantic Kernel solutions using shared guidance plus language-specific references for .NET and Python.
github