Zoho 邮箱集成
v2.2.9
io.clawhub.briansmith80/zoho-email-integration
完整的 Zoho Mail 集成:OAuth2、REST API(快 5-10 倍)、Clawdbot /email 命令、HTML 邮件、附件与批量操作。经过安全加固...。
“Security Scanning” 共 753 个结果
v2.2.9
io.clawhub.briansmith80/zoho-email-integration
完整的 Zoho Mail 集成:OAuth2、REST API(快 5-10 倍)、Clawdbot /email 命令、HTML 邮件、附件与批量操作。经过安全加固...。
v0.1.0
io.clawhub.veeramanikandanr48/spring-boot-engineer
在构建 Spring Boot 3.x 应用、微服务或响应式 Java 应用时使用。涉及 Spring Data JPA、Spring Security 6、WebFlux、Spring Cloud 集成时调用。
v1.0.4
io.clawhub.moltcheck/moltcheck
Moltbot 技能安全扫描器。在安装前扫描 GitHub 仓库中的漏洞。
io.github.sickn33/agentic-awesome-skills/kubernetes-hardening
Implement Kubernetes security contexts, Pod Security Standards, and network policies.
io.github.sickn33/agentic-awesome-skills/firebase
Firebase gives you a complete backend in minutes - auth, database, storage, functions, hosting. But the ease of setup hides real complexity. Security rules are your last line of defense, and they're often wrong.
io.github.garrytan/gstack/cso
首席安全官(CSO)模式。(gstack)
io.github.netdata/netdata/triage-codeql
分诊本仓库的 GitHub Code Scanning 告警(CodeQL security-extended 套件)——列出开放告警,按误报/不修复/仅测试使用驳回,经 GitHub REST + GraphQL 查询。当用户要求「review GitHub security alerts」「check CodeQL findings」「triage code scanning」,或提及 Code Scanning、CodeQL、security-extended、github.com/$repo/security/code-scanning 时使用。
io.github.jeremylongshore/claude-code-plugins-plus-skills/sql-injection-detector
检测 SQL 注入,属于 Security Fundamentals 的自动激活 skill。触发词:sql injection detector、sql detector、sql。在处理 SQL 注入检测功能时使用。
io.github.jeremylongshore/claude-code-plugins-plus-skills/kubernetes-rbac-analyzer
分析 RBAC 相关操作,属于 Security Advanced 的自动激活 skill。在做 Kubernetes RBAC 分析或审计时使用。触发词:kubernetes rbac analyzer、kubernetes analyzer。
io.github.cosmix/loom/loom-kubernetes
Kubernetes 部署、集群架构、安全与运维。用于清单、Helm 图表、RBAC、网络策略、Operator/CRD、PodSecurityStandards、故障排查与生产最佳实践。
io.github.github/awesome-copilot/github-actions-hardening
针对 GitHub Actions 工作流文件(.github/workflows/*.yml)的安全加固评审。分析模式匹配器和通用代码 linter 会漏掉的 Actions 威胁模型——不可信输入的脚本注入、高权限触发器运行 fork 代码、可变的 action 引用、权限过大的 token。当被要求评审、审计、加固或保护 GitHub Actions 工作流、编写新工作流,或遇到"这个工作流安全吗""帮我查 CI 安全问题""这里 pull_request_target 为什么危险""帮我 pin actions""收紧 GITHUB_TOKEN 权限"等请求时使用。覆盖 ${{ }} 插值脚本注入、pull_request_target/workflow_run 权限提升、第三方 action 的 SHA 固定、最小权限、GITHUB_ENV/GITHUB_OUTPUT 注入、密钥暴露、OIDC 与长期凭据、公共仓库自托管 runner 的暴露风险。
io.github.a5c-ai/babysitter/mcp-csp-investigation
对沙箱 iframe 中 MCP Apps 的全面内容安全策略(CSP)审计。发现所有网络来源、追溯至源码,并为 registerAppResource 生成 CSP 配置
io.github.PurpleAILAB/Decepticon/soap-wsdl
SOAP / WSDL 漏洞利用——通过 ?wsdl 枚举 WSDL、SOAP envelope 中的 XXE、WS-Addressing 重放、WS-Security UsernameToken 爆破、向 WS-Trust 注入 SAML token、绕过 schema 校验。
io.github.EliasOulkadi/shokunin/kubernetes
在生产环境部署、管理与调试 Kubernetes —— Deployment、Service、Gateway API、服务网格(Istio/Linkerd/Cilium)、eBPF 可观测性(Cilium Hubble)、安全加固(Pod Security Standards、OPA/Kyverno、seccomp、Falco/Tetragon 运行时安全)、Helm、HPA、PDB、拓扑分布以及问题排查。当用户要求编写 K8s 清单、部署到集群、调试 Pod、搭建 Gateway API、配置弹性伸缩或加固集群安全时使用。不用于编写 Dockerfile(请用 docker)、CI/CD 流水线设计(请用 ci-cd)或 Terraform 基础设施(请用 terraform)。
io.github.netdata/netdata/graphql-audit
分诊本仓库的 GitHub Code Scanning 告警(CodeQL security-extended 套件)——列出开放告警,按误报/不修复/仅测试使用驳回,经 GitHub REST + GraphQL 查询。当用户要求「review GitHub security alerts」「check CodeQL findings」「triage code scanning」,或提及 Code Scanning、CodeQL、security-extended、github.com/$repo/security/code-scanning 时使用。
io.github.ComeOnOliver/skillshub/kubernetes-rbac-analyzer
Kubernetes Rbac Analyzer —— Security Advanced 分类下的自动激活技能。触发词:kubernetes rbac analyzer。属于 Security Advanced 技能分类。
io.github.Dicklesworthstone/pi_agent_rust/sql-injection-detector
检测 SQL 注入。属于安全基础类别的自动激活技能。触发条件:sql injection detector。在涉及 sql injection detector 功能时使用,可用触发短语包括 sql injection detector、sql detector、sql。
io.github.Dicklesworthstone/pi_agent_rust/kubernetes-rbac-analyzer
分析 Kubernetes RBAC 权限。属于安全进阶类别的自动激活技能。触发条件:kubernetes rbac analyzer。在分析或审计 kubernetes rbac analyzer 时使用,可用触发短语包括 kubernetes rbac analyzer、kubernetes analyzer、analyze kubernetes rbac r。
io.github.sundial-org/awesome-openclaw-skills/kubernetes
全面的 Kubernetes 与 OpenShift 集群管理技能,覆盖运维、故障排查、清单生成、安全与 GitOps。在以下情况使用本技能:(1) 集群运维:升级、备份、节点管理、扩缩容、监控搭建;(2) 故障排查:Pod 故障、网络问题、存储问题、性能分析;(3) 创建清单:Deployment、StatefulSet、Service、Ingress、NetworkPolicy、RBAC;(4) 安全:审计、Pod Security Standards、RBAC、密钥管理、漏洞扫描;(5) GitOps:ArgoCD、Flux、Kustomize、Helm、CI/CD 流水线、渐进式交付;(6) OpenShift 特性:SCC、Route、Operator、Build、ImageStream;(7) 多云:AKS、EKS、GKE、ARO、ROSA 运维。
io.github.xenitV1/claude-code-maestro/backend-design
顶级后端标准,包括垂直切片架构(Vertical Slice Architecture)、零信任安全与高性能 API 协议。
io.github.aiskillstore/marketplace/backend-dev-guidelines
面向 Supabase Edge Functions + PostgreSQL 的全面后端开发指南。在使用 Supabase(数据库、认证、存储、realtime)、Edge Functions、PostgreSQL、行级安全(RLS)、Resend 邮件、Stripe 支付或 TypeScript 后端模式时使用。涵盖数据库设计、认证流程、Edge Function 模式、RLS 策略、邮件集成、支付处理与部署到 Supabase。
io.github.lllllllama/rigorpilot-skills/paper-context-resolver
README 优先复现深度学习仓库时,据论文原文补全关键复现细节。
io.github.lllllllama/rigorpilot-skills/env-and-assets-bootstrap
为复现目标准备 conda 环境、权重与数据集路径及缓存配置说明。
io.github.leonxlnx/taste-skill/brandkit
生成高端品牌指南板、Logo 系统与视觉识别方案。