灵感菇

AI 技能的自然生态,你的一句话,蔓延出无限连接。

搜索结果

agent

找到 148 个相关结果 / 安全与治理

安全与治理 / 审核评估

agent-supply-chain

agent-supply-chain

648

验证 AI 智能体插件、工具和依赖项的供应链完整性。在以下场景使用此技能: - 为智能体插件或工具包生成 SHA-256 完整性清单 - 验证已安装插件与其发布的清单是否匹配 - 检测智能体工具目录中被篡改、修改或未跟踪的文件 - 审计智能体组件的依赖固定和版本策略 - 为智能体插件推广构建来源链(开发 → 预发布 → 生产) - 任何类似"验证插件完整性"、"生成清单"、"检查供应链"或"签名此插件"的请求

Stars 0
uiauditagentgithub

安全与治理 / 审核评估

X-Twitter 抓取器

x-twitter-scraper

627

在用户需要与 X (Twitter) 交互时使用——搜索推文、查找用户/粉丝、下载媒体、实时监控账号等。

Stars 0
uiperformancesecurityaudit

安全与治理 / 审核评估

mcp-security-audit

mcp-security-audit

624

Audit MCP (Model Context Protocol) server configurations for security issues. Use this skill when: - Reviewing .mcp.json files for security risks - Checking MCP server args for hardcoded secrets or shell injection patterns - Validating that MCP servers use pinned versions (not @latest) - Detecting unpinned dependencies in MCP server configurations - Auditing which MCP servers a project registers and whether they're on an approved list - Checking for environment variable usage vs. hardcoded credentials in MCP configs - Any request like "is my MCP config secure?", "audit my MCP servers", or "check .mcp.json" keywords: [mcp, security, audit, secrets, shell-injection, supply-chain, governance]

Stars 33,113
securityauditagentagents

安全与治理 / 审核评估

elasticsearch-authz

elasticsearch-authz

619

Manage Elasticsearch RBAC: native users, roles, role mappings, document- and field-level security. Use when creating users or roles, assigning privileges, or mapping external realms like LDAP/SAML.

Stars 475
deploymentsecurityauthapi

安全与治理 / 审核评估

elasticsearch-security-troubleshooting

elasticsearch-security-troubleshooting

589

Diagnose and resolve Elasticsearch security errors: 401/403 failures, TLS problems, expired API keys, role mapping mismatches, and Kibana login issues. Use when the user reports a security error.

Stars 475
deploymentsecurityauthapi

安全与治理 / 审核评估

elasticsearch-audit

elasticsearch-audit

588

Enable, configure, and query Elasticsearch security audit logs. Use when the task involves audit logging setup, event filtering, or investigating security incidents like failed logins.

Stars 475
deploymentsecurityauditauth

安全与治理 / 审核评估

hack

hack

571

Entry P0 primary router for HackSkills. Use when the task involves web application testing, API security assessment, recon, vulnerability triage, exploit path planning, or choosing the right next category skill before any deep topic skill.

Stars 634
uitestingsecurityaudit

安全与治理 / 审核评估

reverse-engineer-rpi

reverse-engineer-rpi

559

Reverse-engineer product specs.

Stars 350
securityauditauthprompt

安全与治理 / 审核评估

kibana-audit

kibana-audit

554

Enable and configure Kibana audit logging for saved object access, logins, and space operations. Use when setting up Kibana audit, filtering events, or correlating Kibana and ES audit logs.

Stars 475
deploymentsecurityauditauth

安全与治理 / 审核评估

security-alert-triage

security-alert-triage

539

Triage Elastic Security alerts — gather context, classify threats, create cases, and acknowledge. Use when triaging alerts, performing SOC analysis, or investigating detections.

Stars 476
uisecurityagentalert

安全与治理 / 审核评估

skill-creator

skill-creator

521

Guide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends Codex's…

Stars 277
designuiapirag

安全与治理 / 审核评估

cloud-create-project

cloud-create-project

497

Creates Elastic Cloud Serverless projects (Elasticsearch, Observability, or Security) via the REST API, saves credentials to file, and bootstraps a scoped Elasticsearch API key. Use when creating a new serverless project, provisioning a search or observability environment, or spinning up a new Elastic Cloud project.

Stars 475
uisecurityauthapi

安全与治理 / 审核评估

cloud-access-management

cloud-access-management

489

Manage Elastic Cloud organization access: invite users, assign roles to Serverless projects, and create or revoke Cloud API keys. Use when granting, modifying, or auditing user access.

Stars 475
uiauditauthapi

安全与治理 / 审核评估

linux-lateral-movement

linux-lateral-movement

465

Linux lateral movement playbook. Use after gaining initial access to pivot across Linux hosts via SSH hijacking, credential harvesting, internal pivoting, D-Bus exploitation, sudo token reuse, and shared filesystem abuse.

Stars 635
uxtestingkubernetessecurity

安全与治理 / 审核评估

AI/ML 安全

ai-ml-security

451

AI/ML 安全手册。用于评估模型供应链攻击(pickle RCE、投毒权重)、对抗样本、模型投毒、模型窃取、数据隐私攻击(成员推断、模型逆向)以及自主智能体安全风险。

Stars 0
securityragllmprompt

安全与治理 / 审核评估

skill-security-audit

skill-security-audit

447

Detect malicious patterns in AI Agent skills — 13 detectors for backdoors, credential theft, data exfiltration, and supply-chain attacks. Based on SlowMist's…

Stars 8
uisecurityauditagent

安全与治理 / 审核评估

arize-trace

arize-trace

444

下载、导出并检查现有的 Arize traces 和 spans,以了解 LLM 应用的运行状态或调试运行时问题。涵盖按 ID 导出 traces、…

Stars 19
uisecurityauthllm

安全与治理 / 审核评估

swift-security

swift-security

438

Use when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID),…

Stars 589
backenduideploymentsecurity

安全与治理 / 审核评估

prompt-guard

prompt-guard

384

Detect and neutralize prompt injection attacks in OpenClaw skill content, user inputs, and external data sources.

Stars 52
securityapipromptagent

安全与治理 / 审核评估

arize-evaluator

arize-evaluator

366

在 Arize 上处理 LLM-as-judge 评估工作流,包括创建/更新评估器、在 span 或 experiment 上运行评估、管理任务等。

Stars 19
designuisecurityauth

4 / 8