quarkus-verification(Quarkus 验证闭环)
io.github.affaan-m/ECC/quarkus-verification
Quarkus 项目的验证闭环:发布或 PR 前的构建、静态分析、带覆盖率的测试、安全扫描、原生编译与差异(diff)审查。
“Security Scanning” 共 753 个结果
io.github.affaan-m/ECC/quarkus-verification
Quarkus 项目的验证闭环:发布或 PR 前的构建、静态分析、带覆盖率的测试、安全扫描、原生编译与差异(diff)审查。
io.github.affaan-m/ECC/django-verification
Django 项目的验证闭环:发布或 PR 前的数据库迁移、代码风格检查、带覆盖率的测试、安全扫描与部署就绪检查。
io.github.cathrynlavery/diagram-design/diagram-design
Create branded architecture, IT current-state, flowchart, sequence, state machine, ER/data model, timeline, swimlane, quadrant, radar/spider, polar chart (polar/radial lollipop), loop/flywheel, nested, tree, org chart, layer stack, Venn, pyramid/funnel, treemap, heatmap, bar, waterfall, line, Gantt and scatter charts, high-level, process, medallion, data flow, DP integration, DP security matrix, Sankey, fishbone, Wardley map, kanban, user journey, deployment, dependency graph, UML class, story map, or database schema diagrams as HTML/SVG/PNG, with .drawio and .excalidraw import support, plus lifecycle phase maps and onboarding guidance.
io.github.zhaoxuya520/reverse-skill/skills
把逆向工程、漏洞利用、渗透测试、恶意软件、移动端、固件、浏览器自动化、文档与安全类任务路由到合适的专项技能。当任务横跨多个模块、或不确定该用哪个 reverse-skill 入口时使用。
io.github.sickn33/agentic-awesome-skills/gcp-cloud-sql
Provision Cloud SQL and Spanner databases. Configure high availability, backups, and security. Use when deploying managed databases on GCP.
io.github.sickn33/agentic-awesome-skills/aws-rds
Provision and manage RDS databases. Configure backups, replication, and security. Use when deploying managed relational databases on AWS.
io.github.sickn33/agentic-awesome-skills/azure-sql
Provision Azure SQL Database and Cosmos DB. Configure security, backups, and replication. Use when deploying managed databases on Azure.
io.github.google/skills/gke-workload-identity
Diagnoses Workload Identity Federation for GKE authentication failures for Pods (403 "iam.serviceAccounts.getAccessToken" / permission denied, "could not find default credentials", or GKE metadata server unreachable) by verifying cluster and node-pool Workload Identity configuration, the Kubernetes ServiceAccount (KSA) to IAM binding (direct principal binding and legacy Google ServiceAccount impersonation), target-resource IAM roles, and gke-metadata-server health. Use when a Pod cannot authenticate to Google Cloud APIs even though Workload Identity is expected to be in effect. Don't use for in-cluster Kubernetes RBAC errors (API-server authorization), general workload crashes (use gke-workload-troubleshooting), or Workload Identity setup and hardening (use gke-workload-security).
io.github.google/skills/gke-upgrades
为标准与 Autopilot 集群规划、执行并验证 Google Kubernetes Engine(GKE)集群升级与维护操作。产出升级计划、升级前后检查清单、含 gcloud 命令的维护 Runbook、发布通道策略与故障排查指南。处理节点池升级策略(surge、蓝绿)、版本兼容、PDB 管理,以及有状态、GPU、operator 等工作负载的特定关注点。每当用户提及 GKE 升级、Kubernetes 版本升级、节点池维护、GKE 打补丁、集群版本管理、发布通道选择、维护窗口、surge 升级、卡住的升级,或任何 GKE 生命周期管理任务——即便是随意的「我们需要升级集群」或「规划下次 GKE 维护」或「我们的升级卡住了」——都使用本技能。不用于 GKE 集群创建、应用接入、一般网络/路由配置或安全策略配置(改用 gke-basics 或相关 GKE 技能)。
io.github.google/skills/gke-manifest-generation
为 GKE Autopilot 与 GKE Standard 集群生成并更新安全、可用于生产的 Kubernetes YAML 清单。用于创建或修改 GKE 部署清单、配置容器安全上下文、设置 CPU/内存资源限制、定义就绪/存活/启动探针、挂载 Secret 与卷、配置 GKE Gateway API 路由、面向 Spot VM,或部署 AI 模型推理工作负载(vLLM、TGI、Gemma)。不用于实时集群操作、Pod 排障(用 gke-workload-troubleshooting)或集群基础设施供给(用 gke-cluster-creation)。
io.github.NousResearch/hermes-agent/requesting-code-review
提交前评审:安全扫描、质量门禁与自动修复。
io.github.pytorch/pytorch/pr-review
审查 PyTorch 的 pull request,关注代码质量、测试覆盖、安全与向后兼容。在审查 PR、被要求审查代码变更,或用户提到「review PR」「code review」「check this PR」时使用。
io.github.electron/electron/chrome-release-cls
给定 Chrome Releases 博客文章 URL(chromereleases.googleblog.com),提取其中每条 CVE/bug,并通过检索本地 Chromium 检出及子仓库定位修复对应的 Gerrit CL。当被要求把 Chrome 安全发布说明映射到修复 CL,或找出对应某次 Chrome 稳定版更新中 CVE 的 commit 时使用。
io.github.electron/electron/chrome-release-verify
针对 Electron 发布分支的端到端 Chrome 安全回移植。给定 Chrome Releases 博客 URL 与分支(如 41-x-y),判定真实同步源码中缺少哪些 CVE 修复,在本地编写 cherry-pick 补丁,用 e sync --3 + lint --patches 验证,最后推单个 PR。当被要求把 Chrome 安全更新回移植到 N-x-y、确认“CVE-X 是否已进 N-x-y”,或为发布分支产出/验证 cherry-pick 补丁集时使用。
io.github.affaan-m/ECC/github-ops
GitHub 仓库的运维、自动化与管理。基于 gh CLI 完成 issue 分类、PR 管理、CI/CD 操作、发布管理与安全监控。当用户需要管理 GitHub issue、PR、CI 状态、发布、贡献者、陈旧条目,或处理超出简单 git 命令范围的 GitHub 运维任务时使用。
io.github.addyosmani/agent-skills/doubt-driven-development
让每个非平凡决策在生效前接受全新上下文的对抗性审查。在你想在推进前交叉质询每个假设、对计划做隐性失败模式压力测试、正确性比速度更重要、在不熟悉的代码中工作、风险高企(生产认证、安全敏感逻辑、高风险迁移、不可逆操作),或任何「现在就验证比日后再调试更划算」的时刻使用。
io.github.koala73/worldmonitor/fetch-country-brief
按 ISO 3166-1 alpha-2 国家代码,获取当前的 AI 生成战略情报简报。当用户询问某国当前地缘政治、经济或安全局势摘要时使用。
io.github.supabase/supabase/safe-sql-execution
只要代码会构建、返回、拉取或执行针对用户真实 Postgres 数据库的 SQL,就使用本 skill——即使需求读起来像普通功能或 bug 修复,完全没提“security”“injection”或“SafeSqlFragment”。覆盖:编写或修改任何构造/返回数据库对象(表、视图、函数、DB 触发器、索引、RLS 策略)SQL 的 pg-meta 函数、查询构造器或接口;把 schema/表/列/搜索词/路由参数插入 SQL 文本;存储、读取或重跑从数据库往返的 SQL(策略定义、函数/视图定义、片段保存内容);以及任何把 SQL 发到项目库的 Run/Apply/Execute 动作(SQL 编辑器执行选中、策略编辑器应用、片段执行器)。在动手写这类代码前就要加载,不要只在评审成品 diff 时才用。仅在改动完全不涉及 SQL 文本或执行时跳过——样式、无关的数据 hook、非 SQL 表单校验或 UI 布局工作。
io.github.zhaoxuya520/reverse-skill/pentest-tools
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
io.github.usestrix/strix/managed-pentesting-with-strix
通过 strix cloud CLI 或 REST API 在 app.strix.ai 平台上对 Web 应用、API、仓库或本地工作区进行托管式渗透测试,无需本地 Docker 或 LLM key。可安全审阅并上传本地源码、注册资产、启动并轮询扫描、分诊漏洞、导出 SARIF、下载合规报告、启动 PR 审查、购买额度和配置定时任务或 webhook。适用于托管式、持续、定时、团队跟踪或沙箱 agent 的安全测试。
io.github.thedotmack/claude-mem/version-bump
Claude Code 插件的自动化语义版本管理与发布工作流。处理 package.json、marketplace.json、plugin.json 清单间的版本号递进、构建验证、git 打标、GitHub release 与 changelog 生成。因维护者提出 npm 安全问题,NPM 发布作为最后需要人工介入的交接环节。
io.github.sickn33/agentic-awesome-skills/mobile-reverse
授权范围内的 Android/iOS 应用逆向与安全测试:APK/IPA 分析、运行时插桩(Frida/Objection)、SSL-pinning 与越狱/ROOT 检测绕过,遵循 OWASP MASTG。
io.github.sickn33/agentic-awesome-skills/cloud-k8s
授权范围内的云、容器与 Kubernetes 安全评估:metadata SSRF、IAM 配置错误、容器逃逸路径与集群 RBAC 审查。
io.github.bentoml/BentoML/bentoml-ec2-deploy
用 Docker 将容器化的 BentoML 服务直接部署到一台或多台裸 AWS EC2 实例——不用 Kubernetes。接收已推送的容器镜像(由 bentoml-containerize 技能构建),或通过 SSH 使用用户既有实例,或经 AWS CLI 开通新实例(SSM AMI 查询、安全组、密钥对),以重启自恢复方式运行容器,并用真实推理请求验证。当用户说“deploy my BentoML service to EC2”“run my bento on an AWS VM”“deploy this bento image to an EC2 instance”“run my BentoML container on AWS without Kubernetes”“put my bento on a cloud VM”等时使用。Kubernetes 目标请改用 bentoml-k8s-deploy。