ZooWork
ZooWork Market

发现 Skills

为真实工作流程挑选经过整理的 Skill,连接、安装并开始使用。

detect-snowflake-replication-config-change

msaad00

Detect creation or modification of Snowflake account-replication or database-replication configurations to accounts not on the authorized list. Reads OCSF 1.8 API Activity (class 6003) records normalized from `account_usage.query_history` carrying the Snowflake-shaped `unmapped.snowflake.{database_name,target_accounts,operation_kind}` block and emits an OCSF 1.8 Detection Finding (class 2004) tagged with MITRE ATT&CK T1537 Transfer Data to Cloud Account whenever `ALTER ACCOUNT SET REPLICATION ENABLED` or `ALTER DATABASE ... ENABLE REPLICATION TO ACCOUNTS (...)` targets an account NOT in `SNOWFLAKE_AUTHORIZED_REPLICATION_TARGETS`. Default allowlist is empty and the detector fails open with a stderr warning when no allowlist is configured. Use when you suspect a compromised credential is setting up exfiltration of an entire database to an attacker-controlled Snowflake account. Do NOT use on raw Snowflake QUERY_HISTORY rows — normalize them through the upstream Snowflake ingest pipeline first. Do NOT use as a generic data-replication detector for non-Snowflake providers.

fal-ai-media

mturac

Unified media generation via fal.ai MCP — image, video, and audio. Covers text-to-image (Nano Banana), text/image-to-video (Seedance, Kling, Veo 3), text-to-speech (CSM-1B), and video-to-audio (ThinkSound). Use when the user wants to generate images, videos, or audio with AI.

mcp-builder

MubasherMohammed

Guide the creation of high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when the user wants to build an MCP server to integrate an external API or service, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).

GWAS sumstats analysis

MubasherMohammed

1. Read the summary statistics file. 2. Identify genome-wide significant lead variants. 3. Compute the genomic inflation factor lambda. 4. Produce a QQ plot under `output/`. 5. Write a final summar...

analyzing-lnk-file-and-jump-list-artifacts

mukkuul976

Analyze Windows LNK shortcut files and Jump List artifacts to establish evidence of file access, program execution, and user activity using LECmd, JLECmd, and manual binary parsing of the Shell Link Binary format.

lnk-filesjump-listslecmdjlecmd

analyzing-threat-actor-ttps-with-mitre-navigator

mukkuul976

Map advanced persistent threat (APT) group tactics, techniques, and procedures (TTPs) to the MITRE ATT&CK framework using the ATT&CK Navigator and attackcti Python library. The analyst queries STIX/TAXII data for group-technique associations, generates Navigator layer files for visualization, and compares defensive coverage against adversary profiles. Activates for requests involving APT TTP mapping, ATT&CK Navigator layers, threat actor profiling, or MITRE technique coverage analysis.

mitre-attacknavigatorthreat-intelligenceapt

conducting-internal-reconnaissance-with-bloodhound-ce

mukkuul976

Conduct internal Active Directory reconnaissance using BloodHound Community Edition to map attack paths, identify privilege escalation chains, and discover misconfigurations in domain environments.

red-teamreconnaissancebloodhoundactive-directory

performing-nist-csf-maturity-assessment

mukkuul976

The NIST Cybersecurity Framework (CSF) 2.0, released in February 2024, provides a comprehensive taxonomy for managing cybersecurity risk through six core Functions - Govern, Identify, Protect, Detect, Respond, and Recover. This skill covers conducting a maturity assessment against the CSF using Implementation Tiers to measure organizational cybersecurity posture and create improvement roadmaps.

compliancegovernancenistcsf

performing-red-team-phishing-with-gophish

mukkuul976

Automate GoPhish phishing simulation campaigns using the Python gophish library. Creates email templates with tracking pixels, configures SMTP sending profiles, builds target groups from CSV, launches campaigns, and analyzes results including open rates, click rates, and credential submission statistics for security awareness assessment.

performingredteamphishing

detecting-golden-ticket-attacks-in-kerberos-logs

mukul975

Detect Golden Ticket attacks in Active Directory by analyzing Kerberos TGT anomalies including mismatched encryption types, impossible ticket lifetimes, non-existent accounts, and forged PAC signatures in domain controller event logs.

threat-huntinggolden-ticketkerberosactive-directory

exploiting-bgp-hijacking-vulnerabilities

mukul975

Analyzes and simulates BGP hijacking scenarios in authorized lab environments to assess route origin validation, RPKI deployment, and BGP monitoring defenses against prefix hijacking and route leak attacks on internet routing infrastructure.

network-securitybgprouting-securityrpki

implementing-runtime-application-self-protection

mukul975

Deploy Runtime Application Self-Protection (RASP) agents to detect and block attacks from within application runtime, covering OpenRASP integration, attack pattern detection, and security policy configuration for Java and Python web applications.

raspapplication-securityopenraspruntime-protection

implementing-threat-modeling-with-mitre-attack

mukul975

Implements threat modeling using the MITRE ATT&CK framework to map adversary TTPs against organizational assets, assess detection coverage gaps, and prioritize defensive investments. Use when SOC teams need to align detection engineering with threat landscape, conduct threat assessments for new environments, or justify security tool procurement.

socmitre-attackthreat-modelingttp

performing-mobile-app-certificate-pinning-bypass

mukul975

Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques using Frida, Objection, and custom scripts. Activates for requests involving certificate pinning bypass, SSL pinning defeat, mobile TLS interception, or proxy-resistant app testing.

mobile-securityandroidioscertificate-pinning

None

mukul975

Discover and inventory all privileged accounts across enterprise infrastructure including domain admins, local admins, service accounts, database admins, cloud IAM roles, and application admin account

iamidentityaccess-controlprivileged-access

performing-web-application-firewall-bypass

mukul975

Bypass Web Application Firewall protections using encoding techniques, HTTP method manipulation, parameter pollution, and payload obfuscation to deliver SQL injection, XSS, and other attack payloads past WAF detection rules.

waf-bypasswaf-evasionsql-injectionxss

testing-api-security-with-owasp-top-10

mukul975

Systematically assessing REST and GraphQL API endpoints against the OWASP API Security Top 10 risks using automated and manual testing techniques.

penetration-testingapi-securityowasprest-api

testing-for-open-redirect-vulnerabilities

mukul975

Identify and test open redirect vulnerabilities in web applications by analyzing URL redirection parameters, bypass techniques, and exploitation chains for phishing and token theft.

open-redirecturl-redirectphishingowasp

conducting-linddun-threat-modeling

mukul975

Complete guide to LINDDUN privacy threat modeling methodology covering seven threat categories: Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness, and Non-compliance. Includes DFD-based analysis, threat tree catalogs, mitigation mapping to privacy design patterns, and step-by-step process.

multi-agent-patterns

muratcankoylan

This skill should be used when the user asks to "design multi-agent system", "implement supervisor pattern", "create swarm architecture", "coordinate multiple agents", or mentions multi-agent patterns, context isolation, agent handoffs, sub-agents, or parallel agent execution.

pest-testing-setup

mwguerra

Set up Pest testing with Orchestra Testbench for Laravel packages

run-test

mx-space

Run tests. Supports running all tests, single file, or pattern-matched tests.

technical-writer

nahisaho

technical-writer skill Trigger terms: documentation, technical writing, API documentation, README, user guide, developer guide, tutorial, runbook, technical docs Use when: User requests involve technical writer tasks.

slim-changelog

NASA-AMMOS

Create and maintain human-readable changelogs for software projects using Keep a Changelog standards. Use when creating project changelogs, documenting releases, managing version history, or establishing transparent communication about software changes for users and contributors.

上一页第 556 / 1401 页下一页