搜索结果
全部能力
找到 185 个相关结果 / 研究资料
安全与治理 / 审核评估
modern-python
modern-python
Configures Python projects with modern tooling (uv, ruff, ty). Use when creating projects, writing standalone scripts, or migrating from pip/Poetry/mypy/black.
安全与治理 / 审核评估
CodeQL
codeql
使用 CodeQL 的跨过程数据流和污点追踪分析扫描代码库中的安全漏洞。触发词包括 "run codeql"、"codeql scan"、"codeql analysis"、"build codeql database" 或 "find vulnerabilities with codeql"。支持 "run all"(security-and-quality + security-experimental 套件)和 "important only"(高精度安全发现)扫描模式。同时支持创建 data extension 模型和处理 CodeQL SARIF 输出。
安全与治理 / 审核评估
secure-workflow-guide
secure-workflow-guide
Guides through Trail of Bits' 5-step secure development workflow. Runs Slither scans, checks special features (upgradeability/ERC conformance/token…
安全与治理 / 审核评估
geo-content-optimizer
geo-content-optimizer
Use when the user asks to "optimize for AI citations"; improves citation readiness for ChatGPT, Perplexity, AI Overviews, Gemini, and Claude. AI引用优化/GEO优化/AI搜索
安全与治理 / 审核评估
content-quality-auditor
content-quality-auditor
Use when auditing content quality, E-E-A-T, publish readiness, or 内容质量/EEAT评分. Runs 80-item CORE-EEAT scoring with veto checks and fix plan.
安全与治理 / 审核评估
serp-analysis
serp-analysis
Use when the user asks to "analyze SERPs"; reviews ranking factors, features, intent, AI Overviews, and snippets. SERP分析/搜索结果
安全与治理 / 审核评估
code-maturity-assessor
code-maturity-assessor
Systematic code maturity assessment using Trail of Bits' 9-category framework. Analyzes codebase for arithmetic safety, auditing practices, access controls,…
安全与治理 / 审核评估
performance-reporter
performance-reporter
Use when generating SEO/GEO reports, traffic summaries, ranking reports, KPI dashboards, stakeholder updates, or monthly reports. SEO报告/绩效仪表盘
安全与治理 / 审核评估
domain-authority-auditor
domain-authority-auditor
Use when auditing domain authority, trust, citations, or 域名权威/网站可信度. Runs 40-item CITE scoring with veto checks.
安全与治理 / 审核评估
gog
gog
Google Workspace CLI for Gmail, Calendar, Drive, Contacts, Sheets, and Docs.
安全与治理 / 审核评估
海关贸易合规
customs-trade-compliance
涵盖多个司法管辖区的海关单证、关税归类、关税优化、受限制方筛查和监管合规的体系化专业知识。由拥有15年以上经验的贸易合规专家提供支持。包含HS归类逻辑、国际贸易术语应用、自由贸易协定(FTA)利用及违规处罚规避。适用于处理海关清关、关税归类、贸易合规、进出口单证或关税优化等场景。
安全与治理 / 审核评估
fp-check
fp-check
Systematically verifies suspected security bugs to eliminate false positives. Produces TRUE POSITIVE or FALSE POSITIVE verdicts with documented evidence for…
安全与治理 / 审核评估
sharp-edges
sharp-edges
Identifies error-prone APIs, dangerous configurations, and footgun designs that enable security mistakes. Use when reviewing API designs, configuration…
安全与治理 / 审核评估
audit-context-building
audit-context-building
Enables ultra-granular, line-by-line code analysis to build deep architectural context before vulnerability or bug finding.
安全与治理 / 审核评估
property-based-testing
property-based-testing
Provides guidance for property-based testing across multiple languages and smart contracts. Use when writing tests, reviewing code with…
安全与治理 / 审核评估
gh-cli
gh-cli
Enforces authenticated gh CLI workflows over unauthenticated curl/WebFetch patterns. Use when working with GitHub URLs, API access, pull requests, or issues.
安全与治理 / 审核评估
solana-vulnerability-scanner
solana-vulnerability-scanner
Scans Solana programs for 6 critical vulnerabilities including arbitrary CPI, improper PDA validation, missing signer/ownership checks, and sysvar spoofing.…
安全与治理 / 审核评估
entry-point-analyzer
entry-point-analyzer
Analyzes smart contract codebases to identify state-changing entry points for security auditing. Detects externally callable functions that modify state,…
安全与治理 / 审核评估
semgrep-rule-creator
semgrep-rule-creator
Creates custom Semgrep rules for detecting security vulnerabilities, bug patterns, and code patterns. Use when writing Semgrep rules or building custom static…
安全与治理 / 审核评估
audit-prep-assistant
audit-prep-assistant
Prepares codebases for security review using Trail of Bits' checklist. Helps set review goals, runs static analysis tools, increases test coverage, removes…