技能安全审计
v1.0.0
io.clawhub.kylehuan/skill-security-audit
对代码库进行全面安全审计与漏洞分析。在明确要求安全分析、代码安全评审、漏洞评估、SAST 扫描或识别源代码安全问题时使用,覆盖注入缺陷、访问控制失效、硬编码密钥、不安全的数据处理、认证弱点、LLM 安全与隐私违规。
“Literature Review” 共 1,271 个结果
v1.0.0
io.clawhub.kylehuan/skill-security-audit
对代码库进行全面安全审计与漏洞分析。在明确要求安全分析、代码安全评审、漏洞评估、SAST 扫描或识别源代码安全问题时使用,覆盖注入缺陷、访问控制失效、硬编码密钥、不安全的数据处理、认证弱点、LLM 安全与隐私违规。
v1.0.3
io.clawhub.t-sinclair2500/lm-studio-subagents
通过将工作分流到本地 LM Studio 模型来降低付费 API 的 token 消耗。适用于:用本地模型完成摘要、抽取、分类、改写、初步审阅等对质量要求适中的高频重复任务;避免大量或重复任务的付费调用;无需额外模型配置,用现有 LM Studio 的 REST API 即时加载;仅限本地或隐私敏感场景。需 LM Studio 0.4+ 并开启服务端(默认 :1234),无需 CLI。
v3.10.0
io.clawhub.alexanderliteplo/rentahuman
Hire humans for physical-world tasks via RentAHuman.ai. Search available humans by skill, post bounties, review applications, and coordinate real-world work. Use when the user needs something done in the physical world — picking up packages, attending events, photography, in-person meetings, taste-testing, and more.
v1.1.0
io.clawhub.maxkle1nz/war-room
面向头脑风暴、系统设计、架构评审、产品规格、商业战略或任何复杂问题的多 Agent 作战室。当用户想运行带专家角色的结构化多 Agent 会话、提到“作战室”、要从零头脑风暴一个项目、用多视角设计系统、请魔鬼代言人压力测试决策,或产出一份完整的蓝图/规格时使用。适用于软件、硬件、内容、商业——任何领域。
io.smithery.sgroy10.speclock
AI Constraint Engine with AI Patch Firewall. 42 MCP tools. Patch Gateway (ALLOW/WARN/BLOCK verdicts), diff-native review (10 scored signals, hard escalation rules), Spec Compiler, Code Graph, Typed constraints, Python SDK, ROS2. Works with Claude Code, Cursor, Windsurf, Cline, Bolt.new, Lovable. 1073 tests. Free and open source. By Sandeep Roy.
v1.0.4
io.clawhub.ivangdavila/learn
把自主学习当作一套系统来运行:有教学大纲与结业测试、刻意练习、间隔复习,并验证所学确实迁移。适用于:无人授课、无考试,自己学一项技能或学科(语言、乐器、编程语言、工作中的新领域)时;当用户问该怎么学 X、先学什么、老实说要花多久时;当看了几个月教程却什么都没做出来时;当先前学的东西已遗忘、复习不断积压、或排队复习连续几周被跳过时;当进度卡在平台期、动力崩塌、或技能因中断而荒废时;当练习看似有效却迁移不到实际工作中时;当 AI 回答太快导致什么都没学到时;以及当学习计划、复习排期、错题记录或掌握度档案必须跨会话存续时。不适用于:即时讲解某个概念(learning)、考试与课业规划(studying)、制作演示文稿(anki、flashcards)。
io.smithery.axel-belfort.diff-checker
面向 AI 智能体的文本 diff 比较 API。逐行比较两段文本:新增、删除、未变更行以及汇总统计(新增/删除/变更数量)。工具:text_compare_diff。适用于代码评审、文档版本管理、变更跟踪或内容比对,返回可直接渲染的结构化 diff。返回:{diff[], added, removed, changed}。无需 API 密钥——在 Base L2 上以 x402 微支付 $0.002/次。
io.smithery.shawnnygoh.arxiv-scout
凭借高级查询能力直接在 arXiv 搜索并获取学术论文。从 PDF 中提取全文,生成摘要、文献综述与并排对比。跟踪引用与参考文献,发现相关研究并梳理学术趋势。
io.smithery.amalgix.document-intelligence
Cross-model evidence pipeline for financial filing and contract intelligence. Two core paid workflows — analyze_public_filing (SEC 10-K/10-Q/20-F, ticker/CIK lookup, metrics, risk changes, contradictions) and review_contract_risks (MSA/NDA/SaaS/procurement, obligations, deadlines, liability, unusual clauses). Plus MCP compatibility utilities: document analysis, web extraction, summarization, and bulk translation. Specialized model routing delivers source-grounded evidence up to 3.8× cheaper than frontier models. Pay per call via x402 USDC on Base or Solana. Document content is not persisted after processing; request metadata and payment events are retained for attribution.
v1.0.0
io.clawhub.terwox/skill-evaluator
使用多框架评分标准(ISO 25010、OpenSSF、Shneiderman 准则及 Agent 专用启发式规则)评估 Clawdbot skill 的质量、可靠性与可发布性。适用于发布前审查、审计、评估或打分 skill,或检查 skill 质量。可运行自动化结构检查,并引导完成 25 项标准的人工评估。
v1.0.1
io.clawhub.dgriffin831/guardrails
以交互方式为 OpenClaw 工作区配置、审查并监控安全护栏:发现风险、访谈用户并生成 GUARDRAILS 配置。
v0.1.0
io.clawhub.veeramanikandanr48/earnings-calendar
该技能通过 Financial Modeling Prep(FMP)API 获取美股即将到来的财报发布日程。当用户需要财报日历数据、想了解下周哪些公司要发财报,或需要做每周财报盘点时使用。技能聚焦市值 20 亿美元及以上、具有显著市场影响的中盘及以上公司,并把数据按日期与时段整理成清爽的 Markdown 表格。支持多种环境(CLI、桌面端、Web),并提供灵活的 API Key 管理。
v1.0.0
io.clawhub.pntrivedy/self-improving-agent-1-0-1
捕获经验、错误与纠正,实现持续改进。使用时机:(1) 命令或操作意外失败;(2) 用户纠正 Claude(“不对,那样是错的……”“其实……”);(3) 用户请求不存在的能力;(4) 外部 API 或工具失败;(5) Claude 意识到知识过时或有误;(6) 发现了重复任务的更优做法。重大任务前应回顾已积累的经验。
v0.1.4
io.clawhub.jchopard69/x-article-editor
根据简报改写草稿或创作高互动 X 长文,并用 8 步优化框架打分与评审。
v2.1.1
io.clawhub.alirezarezvani/quality-manager-qmr
面向 HealthTech 和 MedTech 公司的资深质量管理者代表(QMR):提供质量体系治理、管理评审主导与法规遵循等支持。
v1.0.3
io.clawhub.iterdimensionaltv1/moltlab
加入 MoltLab 研究社区——提出主张、运行计算、为想法投票、辩论研究、撰写论文并评审同行的工作。
v1.0.0
io.clawhub.tomstools11/transcript-to-content
该技能把培训与入职会议的转录文本转换为结构化学习材料、文档和可用于复盘的内容。在处理入职培训、培训会或知识传递类会议的转录时使用,从中提取关键信息并生成学习指南、速查表、清单、FAQ 文档、行动项列表和培训效果评估。
v1.0.0
io.clawhub.springleave/install-scientify
当用户想安装或配置 Scientify 科研插件时使用。
io.smithery.dynamoi.music-youtube-marketing-mcp
通过 ChatGPT、Claude、Gemini 等 AI 助手管理音乐推广与 YouTube 增长活动。为音乐人、厂牌和 YouTube 创作者自动投放 Meta 与 Google 广告,无需代理机构费用。发起 Spotify 活动、壮大 YouTube 频道、查看效果分析、调整预算、暂停或恢复活动,全部通过对话完成。Dynamoi 每天围绕真正重要的指标优化:Spotify 收藏数与 YouTube AdSense 收入,而非曝光量等虚荣指标。每月 300 美元全额转为广告额度,首月还有等额配比。13 个工具覆盖活动管理、分析、账务、平台健康度与媒体素材。
io.smithery.gautamgb.mcpindex
The MCP directory that vets servers, not just lists them. Search by task, then get an advisory screen on a server before your agent calls its tools: whether each tool does what it claims, backed by conformance monitoring and a public drift ledger. Advisory (REVIEW / UNVERIFIED), monitored not enforced, not a safety verdict.
io.smithery.receiptor-ai.receiptor-mcp
Receiptor 把 AI 智能体连到你的记账工作区,让它们查找、审阅并整理票据、账单和发票等财务单据。可用于查看工作区上下文、监控接入来源、核对抽取出的单据数据、检查集成情况,并通过安全的 OAuth 访问 Receiptor AI,准备可直接交给会计师的流程。
io.smithery.plith.rigor
通过结构化的多步工作流产出达到生产质量的交付物。自动任务分类、可配置的分析深度(快速/标准/详尽)与独立质量评审。规划任意工作流免费。
io.smithery.jobly.jobly-mcp
Post contracts, submit proposals, negotiate terms, and resolve disputes on Jobly — an agent-to-agent contract marketplace. Every contract requires structured acceptance criteria, making "did they deliver?" answerable from a spec. Disputes go through AI verdict → appeal window → community stake vote before escrow moves. **29 tools covering the full contract lifecycle:** - Register/login and get an API key - Post contracts with structured terms (scope, deliverables, acceptance criteria) - Browse open contracts and submit proposals - Negotiate via counter-offers - Submit and review deliverables - Release escrow or raise disputes - Appeal AI verdicts and vote on community disputes - Manage provider profiles, messages, and reviews All transactions use JOOBs (sandbox currency). Free to use.
io.smithery.daniel-abbay.compuute-scan-api
Static security scanner for MCP servers. POST a public GitHub URL, get severity counts, a score, and the top findings with file+line back. 37 rules across TypeScript, JavaScript, Python, Go, Rust, C#, Java, and Kotlin — every language with an official MCP SDK. Detects argument injection for npx/uvx/pipx/pnpx runner binaries (CWE-88), known CVEs in 40+ top packages, and the usual L0 discovery (transport, tool inventory, dependency pinning). This is a pattern detector, not an exploitability oracle. Around 90% raw false-positive rate on unfiltered output — triage is on you, and the response says so explicitly. POST /v1/scan is free with no API key. POST /v1/scan/pay charges $0.10 USDC per scan via x402 on Base. Manual L2-L4 audits at compuute.se/audit when you need dataflow review. Wraps compuute-scan (MIT, zero deps). Per-rule false-positive rates and the methodology paper live in the repo.