搜索结果
全部能力
找到 351 个相关结果 / 数据分析
安全与治理 / 审核评估
fusion-dependency-review
fusion-dependency-review
Review dependency PRs with structured research, existing-PR-discussion capture, multi-lens analysis (security, code quality, impact), and a repeatable verdict…
安全与治理 / 审核评估
deserialization-insecure
deserialization-insecure
Insecure deserialization playbook. Use when Java, PHP, or Python applications deserialize untrusted data via ObjectInputStream, unserialize, pickle, or similar mechanisms that may lead to RCE, file access, or privilege escalation.
安全与治理 / 审核评估
grepai-search-boosting
grepai-search-boosting
Configure search result boosting in GrepAI. Use this skill to prioritize certain paths and penalize others.
安全与治理 / 审核评估
dynamics-crm
dynamics-crm
Microsoft Dynamics 365 integration. Manage crm and sales data, records, and workflows. Use when the user wants to interact with Microsoft Dynamics 365 data.
安全与治理 / 审核评估
linkedin-personal-branding
linkedin-personal-branding
Comprehensive LinkedIn personal branding analysis, profile optimization, and visibility improvement skill using Claude for Chrome browser tools. Use when users…
安全与治理 / 审核评估
safe-action-advanced
safe-action-advanced
Use when working with bind arguments, metadata schemas, framework errors (redirect/notFound/forbidden/unauthorized), type inference utilities…
安全与治理 / 审核评估
ads-linkedin
ads-linkedin
LinkedIn Ads 深度分析,用于 B2B 广告投放。评估 27 项检查,涵盖技术设置、受众定向、创意质量、销售线索表单和出价策略…
安全与治理 / 审核评估
llm-prompt-injection
llm-prompt-injection
LLM prompt injection playbook. Use when testing AI/LLM applications for direct injection, indirect injection via RAG/browsing, tool abuse, data exfiltration, MCP security risks, and defense bypass techniques.
安全与治理 / 审核评估
hormuz-strait
hormuz-strait
Check the current status of the Strait of Hormuz — shipping transit data, oil price impact, stranded vessels, insurance risk levels, diplomatic developments, and global trade impact. Use this skill whenever the user asks about the Strait of Hormuz, Hormuz chokepoint, Persian Gulf shipping risk, oil transit disruption, war risk premium in the Gulf, Middle East shipping routes, tanker traffic through Hormuz, oil supply chain risk, or geopolitical risk affecting energy markets. Triggers include: "Hormuz status", "Strait of Hormuz", "is Hormuz open", "shipping through the Gulf", "oil chokepoint", "Persian Gulf tanker traffic", "war risk premium", "Hormuz crisis", "energy supply chain risk", "oil transit disruption", "Middle East shipping", any mention of Hormuz or Persian Gulf in context of oil, shipping, or geopolitical risk.
安全与治理 / 审核评估
senior-security
senior-security
Security engineering toolkit for threat modeling, vulnerability analysis, secure architecture, and penetration testing. Includes STRIDE analysis, OWASP…
安全与治理 / 审核评估
nosql-injection
nosql-injection
NoSQL injection playbook. Use when MongoDB-style operators, JSON query objects, flexible search filters, or backend query DSLs may allow data or logic abuse.
安全与治理 / 审核评估
csp-bypass-advanced
csp-bypass-advanced
Advanced Content Security Policy bypass techniques. Use when XSS or data exfiltration is blocked by CSP and you need to find policy weaknesses, trusted endpoint abuse, nonce leakage, or exfiltration channels that CSP cannot block.
安全与治理 / 审核评估
slack
slack
Slack integration. Manage communication data, records, and workflows. Use when the user wants to interact with Slack data.
安全与治理 / 审核评估
rsa-attack-techniques
rsa-attack-techniques
RSA attack playbook for CTF and real-world cryptanalysis. Use when given RSA parameters (n, e, c) and need to recover plaintext by exploiting weak keys, small exponents, shared factors, or padding oracles.
安全与治理 / 审核评估
gdpr-dsgvo-expert
gdpr-dsgvo-expert
Senior GDPR/DSGVO expert and internal/external auditor for data protection compliance. Provides EU GDPR and German DSGVO expertise, privacy impact assessments,…
安全与治理 / 审核评估
AI/ML 安全
ai-ml-security
AI/ML 安全手册。用于评估模型供应链攻击(pickle RCE、投毒权重)、对抗样本、模型投毒、模型窃取、数据隐私攻击(成员推断、模型逆向)以及自主智能体安全风险。
安全与治理 / 审核评估
skill-security-audit
skill-security-audit
Detect malicious patterns in AI Agent skills — 13 detectors for backdoors, credential theft, data exfiltration, and supply-chain attacks. Based on SlowMist's…
安全与治理 / 审核评估
meegle
meegle
飞书项目(Meego/Meegle)操作工具。支持查询和管理工作项、节点流转、视图查询、个人待办、排期统计等功能。 Use when user needs to work with Feishu/Lark Meego project management — including querying work items, creating/updating work items, completing workflow nodes, checking views, listing todos, analyzing schedules/workloads, or searching with MQL. 关键词:飞书项目、meego、meegle、工作项、需求、任务、缺陷、排期、视图、待办、节点。
安全与治理 / 审核评估
arize-trace
arize-trace
下载、导出并检查现有的 Arize traces 和 spans,以了解 LLM 应用的运行状态或调试运行时问题。涵盖按 ID 导出 traces、…
安全与治理 / 审核评估
swift-security
swift-security
Use when working with iOS/macOS Keychain Services (SecItem queries, kSecClass, OSStatus errors), biometric authentication (LAContext, Face ID, Touch ID),…