Use the open-source free `Meziantou.Analyzer` package for design, usage, security, performance, and style rules in...
Security
Security scanning, authentication, and vulnerability detection
信息溯源与信源信誉追踪。追溯信息源头(谁先报的、谁说的最准、原作者是谁),长期积累信源画像。Triggers on: 谁先报的, 谁最先说的, 消息来源, 信息溯源, 最早发布, 首发, 源头, 这个消息可信吗, 这是真的吗,...
Code-level security posture evaluation. Scans for OWASP Top 10 vulnerabilities, authentication flaws, injection...
Use this skill whenever the user wants to do anything with PDF files. This includes reading or extracting...
Configure and enable unattended-upgrades (automatic security/package updates) on Debian/Ubuntu hosts, including...
Add JWT authentication to pico-fastapi controllers. Use when protecting endpoints, adding role-based access control,...
Code quality, security, and performance scan with FIPD-classified findings
Migrate a Base44 app to Vercel (frontend + serverless functions) and Supabase (PostgreSQL + Auth). Scans the repo,...
File, directory, or component to audit
セキュリティ脆弱性検出の判断基準。security-reviewerが使用する専用知識ベース。
Designs a secure authentication and authorization flow for any application, covering login, sessions, roles, and edge cases.
Sync OneLap FIT files to Strava and run auth initialization flows. Use when users ask to sync activities, download...
Binance Spot request using the Binance API. Authentication requires API key and secret key. Supports testnet,...
Binance Margin-trading request using the Binance API. Authentication requires API key and secret key.
Binance Derivatives-trading-usds-futures request using the Binance API. Authentication requires API key and secret...
Binance Assets request using the Binance API. Authentication requires API key and secret key.
Binance Alpha request using the Binance API. Authentication requires API key and secret key.
Audits codebases for common security vulnerabilities that AI coding assistants introduce in "vibe-coded"...
专为产品经理设计的 PRD 协作专家。融合"架构师严谨"与"开发者同理心",通过逻辑推导、风险左移及红队测试,输出逻辑闭环、无歧义的标准化 PRD 文档。支持命令:/prd-coauthor <项目简述>
支持双引擎的PDF OCR识别技能,可从影印版PDF文件和图片文件中提取中英文文字内容 | PDF OCR Skill with dual-engine support, capable of extracting Chinese...
Scan Clawdbot and MCP skills for malware, spyware, crypto-miners, and malicious code patterns before you install...
Scan ClawHub skills for security vulnerabilities BEFORE installing. Use when installing new skills from ClawHub to...
Retrieve and manage secrets from 1Password using the op CLI. Supports item lookup, field access, and environment injection.
Security scanner for OpenClaw skills. Run before installing any skill to detect prompt injection, data exfiltration,...