灵感菇

AI 技能的自然生态,你的一句话,蔓延出无限连接。

搜索结果

全部能力

找到 97 个相关结果 / 测试与 QA

安全与治理 / 审核评估

atheris

atheris

2.3K

Atheris is a coverage-guided Python fuzzer based on libFuzzer. Use for fuzzing pure Python code and Python C extensions.

Stars 5,222
uitestingragatheris

安全与治理 / 审核评估

ruzzy

ruzzy

2.3K

Ruzzy is a coverage-guided Ruby fuzzer by Trail of Bits. Use for fuzzing pure Ruby code and Ruby C extensions.

Stars 5,234
uiuxtestingrag

安全与治理 / 审核评估

laravel-verification

laravel-verification

2.1K

Laravel 项目的验证循环:环境检查、代码规范检查、静态分析、带覆盖率的测试、安全扫描以及部署就绪检查。

Stars 0
uideploymentsecurityaudit

安全与治理 / 审核评估

医疗评估工具套件

healthcare-eval-harness

2.0K

面向医疗应用部署的患者安全评估工具。用于 CDSS 准确性、PHI 泄露、临床工作流完整性等场景的自动化测试套件,……

Stars 0
uijestdeploymentsecurity

安全与治理 / 审核评估

谷歌云方案-网络可观测性

google-cloud-recipe-networking-observability

2.0K

通过分析日志、指标和诊断信息来排查 Google Cloud 网络问题。适用于调查 VPC 流日志、NAT、防火墙或威胁日志,查询延迟和吞吐量指标,或运行 Connectivity Tests 以进行路径诊断。

Stars 0
uiuxperformanceaudit

安全与治理 / 审核评估

ghost-validate

ghost-validate

1.4K

This skill should be used when the user asks to "validate a finding", "check if a vulnerability is real", "triage a security finding", "confirm a…

Stars 408
testingsecurityauthsql

安全与治理 / 审核评估

mutation-testing

mutation-testing

1.0K

Configures mewt or muton mutation testing campaigns — scopes targets, tunes timeouts, and optimizes long-running runs. Use when the user mentions mewt, muton,…

Stars 5,230
testingsqlragmutation

安全与治理 / 审核评估

genotoxic

genotoxic

1.0K

Graph-informed mutation testing triage. Parses codebases with Trailmark, runs mutation testing and necessist, then uses survived mutants, unnecessary test…

Stars 5,228
testinggenotoxicgraphinformed

安全与治理 / 审核评估

ai-scanner-garak

ai-scanner-garak

701

基于 NVIDIA garak 构建的 AI 模型安全扫描器,通过 179 个安全探针对 35 个漏洞家族测试 LLM

Stars 0
uitestingdockersecurity

安全与治理 / 审核评估

security-auditor

security-auditor

670

Expert security auditor specializing in DevSecOps, comprehensive cybersecurity, and compliance frameworks.

Stars 37,704
designuitestingsecurity

安全与治理 / 审核评估

mcp-security-audit

mcp-security-audit

624

Audit MCP (Model Context Protocol) server configurations for security issues. Use this skill when: - Reviewing .mcp.json files for security risks - Checking MCP server args for hardcoded secrets or shell injection patterns - Validating that MCP servers use pinned versions (not @latest) - Detecting unpinned dependencies in MCP server configurations - Auditing which MCP servers a project registers and whether they're on an approved list - Checking for environment variable usage vs. hardcoded credentials in MCP configs - Any request like "is my MCP config secure?", "audit my MCP servers", or "check .mcp.json" keywords: [mcp, security, audit, secrets, shell-injection, supply-chain, governance]

Stars 33,113
securityauditagentagents

安全与治理 / 审核评估

hack

hack

571

Entry P0 primary router for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerability triage, exploit path planning, or choosing the right next category skill before any deep topic skill.

Stars 634
uitestingsecurityaudit

安全与治理 / 审核评估

llm-prompt-injection

llm-prompt-injection

483

LLM prompt injection playbook. Use when testing AI/LLM applications for direct injection, indirect injection via RAG/browsing, tool abuse, data exfiltration, MCP security risks, and defense bypass techniques.

Stars 635
testingsecurityragllm

安全与治理 / 审核评估

senior-security

senior-security

476

Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP…

Stars 15,036
designtestingsecurityworkflow

安全与治理 / 审核评估

hash-attack-techniques

hash-attack-techniques

475

Hash attack playbook. Use when exploiting length extension, MD5/SHA1 collisions, HMAC timing leaks, birthday attacks, or hash-based proof of work in CTF and authorized testing scenarios.

Stars 634
uitestingsecurityauth

安全与治理 / 审核评估

linux-lateral-movement

linux-lateral-movement

465

Linux lateral movement playbook. Use after gaining initial access to pivot across Linux hosts via SSH hijacking, credential harvesting, internal pivoting, D-Bus exploitation, sudo token reuse, and shared filesystem abuse.

Stars 635
uxtestingkubernetessecurity

安全与治理 / 审核评估

macos-security-bypass

macos-security-bypass

455

macOS security bypass playbook. Use when targeting macOS endpoints and need to bypass TCC, Gatekeeper, SIP, sandbox, code signing, or entitlement-based protections during authorized red team or pentest engagements.

Stars 635
uiuxsecurityauth

安全与治理 / 审核评估

security-testing

security-testing

430

Identify security vulnerabilities through SAST, DAST, penetration testing, and dependency scanning. Use for security test, vulnerability scanning, OWASP, SQL injection, XSS, CSRF, and penetration testing.

Stars 219
uitestingsecurityauth

安全与治理 / 审核评估

financial-calculator

financial-calculator

369

Run loan, investment, NPV, retirement, savings, and risk calculations with schedules and charts. Use for deterministic financial modeling tasks.

Stars 53
workflowfinancialcalculatorrun

安全与治理 / 审核评估

scanning-tools

scanning-tools

356

Master essential security scanning tools for network discovery, vulnerability assessment, web application testing, wireless security, and compliance…

Stars 37,704
uiuxtestingsecurity

2 / 5