所有 Skills
找到 8842 个 Skills
Skills 列表

web-coder
精通 Web 开发、网络协议和 Web 标准的 10x 全栈专家。当涉及 HTML、CSS、JavaScript、Web API、HTTP/HTTPS、Web 安全、性能优化、无障碍设计(Accessibility)或任何 Web/互联网相关概念时使用此 Skill。擅长精准解读 Web 专业术语,并在前后端开发中落地现代 Web 标准。
github
edr-bypass-re
逆向防御方实现 → 红队针对性绕过。把 EDR / Defender / AV 的 hook 表、ETW provider、AMSI 实现先逆向出来, 再写针对性的 unhook / 间接 syscall / ETW patch / call stack spoof。对照 MITRE ATT&CK T1562 防御规避。 触发关键词:EDR 绕过、AV bypass、免杀、unhook、direct syscall、indirect syscall、Hell's Gate、Halo's Gate、 Tartarus Gate、ETW patch、AMSI patch、call stack spoofing、hardware breakpoint Blindside、MITRE T1562、 ntdll unhook、kernel callback、CrowdStrike 绕过、Defender 绕过、Sentinel One 绕过、Elastic Defend、 Sysmon 规避、PPID spoof、Sleep mask、Process Hollowing、Reflective DLL。
zhaoxuya520
patch-diff-exploit
N-day 补丁差分到利用。从厂商发布的补丁里反推漏洞点、写 PoC、做成可用的攻击模块。 适用场景:已知 CVE 编号但只有补丁没有 PoC、SRC/红队需要打击未及时更新的资产、N-day 武器化、Patch Tuesday 跟进。 核心方法:拿 before/after 二进制 → 对齐符号 → 二进制 diff → 看新增的安全检查反推 bug class → 写 PoC 触发漏洞。 触发关键词:N-day、Nday、补丁差分、patch diff、patch tuesday、1day、binary diff 漏洞、bindiff 利用、ghidriff、Diaphora、补丁分析、CVE 复现、漏洞还原、补丁反推、N-day 武器化。
zhaoxuya520
pwn-chain
从逆向走到可用利用 (Working Exploit) 的全链路工程化方法。 适用场景:拿到了二进制 + 漏洞点 + 目标环境,需要写出一个能稳定打通的 exploit(不是只能本地复现一下、远程一打就崩的脚本)。 覆盖三大方向:栈溢出 / 堆利用 / 内核 pwn。强调"CTF 本地通 → 真实远程稳定打通"的工程差距:libc 版本错配、堆喷射时序、SMEP/SMAP/KASLR、栈对齐、远程缓冲。 核心工具链:pwntools + GEF/pwndbg + ROPgadget/Ropper + one_gadget + libc-database + qemu-system 内核调试。 触发关键词:pwn、栈溢出、堆溢出、ROP、ret2libc、ret2csu、one_gadget、libc-database、堆利用、tcache、fastbin、unsorted bin、kernel pwn、kROP、SMEP、SMAP、KASLR、modprobe_path、pwntools、GEF、pwndbg。
zhaoxuya520
gsap-framer-scroll-animation
当用户想要构建滚动动画、滚动效果、视差、滚动触发的元素显现、固定区域、水平滚动、文本动画或任何与滚动位置相关的动效时,请使用此技能——适用于原生JS、React或Next.js。涵盖GSAP ScrollTrigger(固定、跟随滚动、吸附、时间线、水平滚动、ScrollSmoother、matchMedia)和Framer Motion / Motion v12(useScroll、useTransform、useSpring、whileInView、variants)。即使用户只说“滚动时动画”、“滚动时淡入”、“像苹果官网那样滚动”、“视差效果”、“粘性区域”、“滚动进度条”或“入场动画”,也应使用此技能。同时适用于Copilot中生成GSAP或Framer Motion代码的提示模式。与premium-frontend-ui技能配合使用,以获得创意理念和设计层面的精良效果。
github
autoresearch
适用于任何编程任务的自主迭代实验循环。引导用户定义目标、可衡量的指标和范围约束,然后运行一个自主循环:代码修改、测试、测量,并保留或丢弃结果。灵感来自 Karpathy 的 autoresearch。用途:自主改进、迭代优化、实验循环、自动研究、性能调优、自动化实验、爬山法、自动尝试、优化代码、运行实验、自主编码循环。不适用于:一次性任务、简单 bug 修复、代码审查,或没有可衡量指标的任务。
github
binary-diff
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。 核心方法:用 LLM 做结构化差异比对,程序化输入输出,成本极低(200 函数 ~1 元)。 触发关键词:符号迁移、bindiff、跨版本、PDB 缺失、函数偏移迁移、symbol migration、binary diff、版本对比。
zhaoxuya520
firmware-pentest
固件 / IoT 渗透链。从拿到一坨 .bin / .img 开始,闭环走完逆向 → 提取 → 模拟 → 利用。 方法论遵循 OWASP FSTM 九阶段;工具链以 binwalk v3、unblob、EMBA、Firmadyne、AFL++ 为主。 适用场景:路由器/摄像头/智能家居固件审计、固件升级包逆向、IoT CVE 复现、嵌入式 0day 挖掘。 触发关键词:固件、firmware、IoT、binwalk、unblob、UART、JTAG、squashfs、UBI、JFFS2、Firmadyne、QEMU 全系统仿真、EMBA、固件渗透、路由器固件、嵌入式漏洞利用、bootloader、NVRAM、FAT、firmware analysis toolkit。
zhaoxuya520
diagram-generator
generate, refine, validate, and render diagrams from natural language, notes, code snippets, schemas, tables, or existing diagram source. use for flowcharts, swimlanes, sequence diagrams, state diagrams, er diagrams, class diagrams, architecture/c4-style diagrams, dependency graphs, gantt charts, mind maps, user journeys, sankey-style flows, org charts, network graphs, and other visual models. supports mermaid by default, graphviz dot for complex graph layout, plantuml for uml-heavy engineering diagrams, and svg output when direct markup is more reliable.
zhaoxuya520
premium-frontend-ui
一份全面的指南,帮助 GitHub Copilot 打造沉浸式、高性能的网页体验,融合高级动效、排版与架构工艺。
github
eval-driven-dev
使用评估驱动开发改进AI应用。定义评估标准、对应用进行插桩、构建黄金数据集、观察和评估应用运行、分析结果,并生成具体的改进行动计划。当用户要求为任何调用LLM模型的Python项目设置QA、添加测试、添加评估、进行基准测试、修复错误行为、改进质量或进行质量保证时,始终使用此技能。
github
doublecheck
AI输出三层验证流水线。提取可验证的声明,通过网络搜索找到支持或矛盾的来源,运行对抗性审查以发现幻觉模式,并生成带有来源链接的结构化验证报告供人工审核。
github
radare2
Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it when the user mentions PE/ELF/Mach-O/DEX/WASM files together with CLI analysis, `rabin2`, `rasm2`, `radiff2`, `r2pipe`, or asks for radare2 command help on Windows/Linux/macOS.
zhaoxuya520
security-review
AI驱动的代码库安全扫描器,像安全研究员一样推理代码——追踪数据流、理解组件交互、捕捉模式匹配工具遗漏的漏洞。当被要求扫描代码安全漏洞、查找错误、检查SQL注入、XSS、命令注入、暴露的API密钥、硬编码密钥、不安全的依赖、访问控制问题,或任何类似“我的代码安全吗?”、“审查安全问题”、“审计此代码库”或“检查漏洞”的请求时,使用此技能。涵盖JavaScript、TypeScript、Python、Java、PHP、Go、Ruby和Rust中的注入缺陷、身份验证和访问控制错误、密钥暴露、弱加密、不安全的依赖以及业务逻辑问题。
github
flowstudio-power-automate-mcp
通过 FlowStudio MCP 使用 Power Automate 的基础技能——身份验证设置、可复用的 MCP 辅助函数(Python + Node.js)、通过 `list_skills` / `tool_search` 发现工具,以及处理超大响应。将代理连接到 Power Automate 时,请先加载此技能。对于专门的工作流,请加载 `flowstudio-power-automate-build`、`flowstudio-power-automate-debug`、`flowstudio-power-automate-monitoring`(Pro+)或 `flowstudio-power-automate-governance`(Pro+)——每个都包含工作流叙述,而此技能提供了它们所依赖的基础设施。需要 FlowStudio MCP 订阅或兼容的服务器——请参阅 https://mcp.flowstudio.app
github
azure-pricing
使用 Azure 零售价格 API (prices.azure.com) 获取实时 Azure 零售定价,并估算 Copilot Studio 代理信用消耗。当用户询问任何 Azure 服务的成本、想要比较 SKU 价格、需要定价数据进行成本估算、提及 Azure 定价、Azure 成本、Azure 计费,或询问 Copilot Studio 定价、Copilot 信用或代理使用估算时使用。涵盖计算、存储、网络、数据库、AI、Copilot Studio 以及所有其他 Azure 服务系列。
github
copilot-spaces
使用 Copilot Spaces 为对话提供项目特定的上下文。当用户提到“Copilot space”、想要从共享知识库加载上下文、发现可用的空间,或提出基于精选项目文档、代码和指令的问题时,使用此技能。
github
pentest-tools
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
zhaoxuya520
winmd-api-search
查找并探索 Windows 桌面 API。适合在开发需要系统/平台能力(如摄像头、文件访问、系统通知、UI 控件、AI/ML、传感器、网络连接等)的功能时使用。能够根据具体需求精准匹配目标 API,并获取完整的类型细节(包括方法、属性、事件及枚举值)。
github
winui3-migration-guide
UWP 到 WinUI 3 迁移参考。将旧版 UWP API 映射到正确的 Windows App SDK 等效项,并附有前后代码片段。涵盖命名空间更改、线程处理(CoreDispatcher 到 DispatcherQueue)、窗口管理(CoreWindow 到 AppWindow)、对话框、选择器、共享、打印、后台任务以及最常见的 Copilot 代码生成错误。
github
copilotkit-self-update
Use when the user wants to update, refresh, or reinstall the CopilotKit agent SKILLS (the SKILL.md files that teach this agent about CopilotKit). NOT for updating the CopilotKit codebase or project — this is specifically about refreshing the skills/knowledge this agent has loaded. Triggers on "update copilotkit skills", "update skills", "refresh skills", "skills are stale", "skills are outdated", "get latest skills", "my copilotkit knowledge is wrong", "copilotkit APIs changed", "skills seem old", "wrong API names", "reinstall skills", "skills not working right", "update your copilotkit knowledge".
copilotkit
react-core
@copilotkit/react-core — mount the CopilotKit provider (from @copilotkit/react-core/v2) in a Next.js App Router / React Router v7 / TanStack Start / SPA app, drop in CopilotChat/CopilotPopup/CopilotSidebar (v2 chat components ship from react-core/v2 — NOT react-ui, which is CSS-only in v2), access and subscribe to agents with useAgent / useAgentContext / useCapabilities, switch between multiple agents, manage durable Intelligence threads with useThreads, register browser-side tools via useFrontendTool, render tool calls with useRenderTool / useComponent / useDefaultRenderTool, gate execution with useHumanInTheLoop, wire file attachments with useAttachments, configure suggestion pills, and register activity- and custom-message renderers. publicLicenseKey is canonical (publicApiKey is deprecated alias). Load the reference under references/ that matches your task.
copilotkit
copilotkit-agui
Use when building custom agent backends, implementing the AG-UI protocol, debugging streaming issues, or understanding how agents communicate with frontends. Covers event types, SSE transport, AbstractAgent/HttpAgent patterns, state synchronization, tool calls, and human-in-the-loop flows.
copilotkit
a2ui-renderer
Render A2UI (Agent-to-UI declarative surfaces) in CopilotKit v2. Enable the runtime via CopilotRuntime({ a2ui: {...} }), then enable the provider via <CopilotKit a2ui={{ theme }}>. Auto-activates via /info — do NOT manually pass renderActivityMessages. createA2UIMessageRenderer ships from @copilotkit/react-core/v2; low-level primitives (A2UIProvider, A2UIRenderer, createCatalog) ship from @copilotkit/a2ui-renderer. Covers theme customization, createSurface dedup, action-bridge try/finally cleanup. Load when an agent emits A2UI operations (createSurface / updateComponents / updateDataModel), when wiring a2ui on CopilotRuntime, or when styling A2UI surfaces.
copilotkit