发现 Skills
为真实工作流程挑选经过整理的 Skill,连接、安装并开始使用。
cspm-aws-cis-benchmark
Assess AWS accounts against CIS AWS Foundations Benchmark v3.0. Runs 18 automated read-only checks across IAM, Storage, Logging, and Networking. Produces per-control pass/fail results with remediation commands. Use when the user mentions AWS CIS benchmark, cloud security posture, IAM hygiene audit, S3 public access check, or CloudTrail validation. Do NOT use for GCP, Azure, or on-prem; do NOT use this skill to remediate findings (it is assessment-only and has zero write permissions) — pair with iam-departures-remediation for IAM cleanup, or open a ticket in your remediation workflow for other findings.
detect-clickhouse-bulk-export
Detect single-principal bulk row export out of a ClickHouse cluster. Reads OCSF 1.8 API Activity (class 6003) records carrying `actor.user.uid`, `api.operation`, and ClickHouse-shaped `unmapped.clickhouse.{query_kind,read_bytes,read_rows,written_bytes,written_rows,query,exception}` fields, groups them by principal across a sliding window, and emits an OCSF 1.8 Detection Finding (class 2004) tagged with MITRE ATT&CK T1567 Exfiltration Over Web Service whenever cumulative `read_bytes` for queries whose SQL text matches an external-export pattern (`INTO OUTFILE`, `INSERT INTO FUNCTION s3(`, `URL(`) crosses the configured byte threshold. Use when you suspect a compromised ClickHouse account or service principal is dumping rows to S3, an external HTTP endpoint, or a local OUTFILE. Do NOT use on raw ClickHouse `system.query_log` rows — normalize them through the upstream ClickHouse ingest pipeline first. Do NOT use as a generic data-loss detector for non-ClickHouse warehouses.
defi-amm-security
DeFi automated market maker (AMM) smart contract security audit patterns. Covers flash loans, slippage, sandwich attacks, price manipulation, reentrancy, and incorrect integer arithmetic.
dmux-workflows
Multi-agent orchestration using dmux (a tmux pane manager for AI agents). Patterns for running parallel agent workflows across OpenAI Codex, Codex, OpenCode, and other harnesses. Use when running multiple agent sessions in parallel or coordinating multi-agent development workflows.
frontend-design-direction
Front-end design direction, aesthetic principles, and implementation of a consistent design language.
nodejs-keccak256
Prevent Ethereum hashing bugs in JavaScript and TypeScript. Node's SHA3-256 is the NIST SHA3, not Ethereum's Keccak-256, and can silently break selectors, signatures, storage slots, and address derivation.
perl-patterns
Idioms, best practices, and conventions for Modern Perl 5.36+ to build robust, maintainable Perl applications.
gget
gget CLI and Python workflow for quick searches of genome databases, sequence searches, BLAST-style searches, enrichment checks, and reproducible bioinformatics evidence logs.
agents-md-improver
Audit and improve project-rules files (AGENTS.md, CLAUDE.md, .agents/instructions, etc.) in repositories. Use when the user asks to check, audit, update, improve, or fix their AGENTS.md or CLAUDE.md, when they mention "project rules maintenance" or "agent context optimization", or after the codebase has changed significantly and the rules file may be stale. Scans for all relevant files, evaluates quality against templates, outputs a quality report, and then makes targeted updates with user approval.
lit-synthesizer
Search PubMed and bioRxiv for bioinformatics literature, synthesise results into a structured report, and build a citation graph — all locally, with a reproducibility bundle.
proteomics-de
Differential expression analysis for label-free quantitative (LFQ) intensity data with standard MaxQuant and DIA-NN output. Workflow includes preprocessing, imputation, and statistical testing.
file-operations
Perform file system operations like creating, reading, listing, and managing files and directories. Use for file management, directory navigation, file creation, file reading, ls, cd, mkdir, pwd commands.
building-incident-timeline-with-timesketch
Build collaborative forensic incident timelines using Timesketch to ingest, normalize, and analyze multi-source event data for attack chain reconstruction and investigation documentation.
investigating-insider-threat-indicators
Investigates insider threat indicators including data exfiltration attempts, unauthorized access patterns, policy violations, and pre-departure behaviors using SIEM analytics, DLP alerts, and HR data correlation. Use when SOC teams receive insider threat referrals from HR, detect anomalous data movement by employees, or need to build investigation timelines for potential insider threats.
performing-threat-intelligence-sharing-with-misp
Use PyMISP to create, enrich, and share threat intelligence events on a MISP platform, including IOC management, feed integration, STIX export, and community sharing workflows.
performing-bluetooth-security-assessment
Assess Bluetooth Low Energy device security by scanning, enumerating GATT services, and detecting vulnerabilities
performing-iot-security-assessment
Performs comprehensive security assessments of IoT devices and their ecosystems by testing hardware interfaces, firmware, network communications, cloud APIs, and companion mobile applications. The tester uses firmware extraction and analysis, hardware debugging via UART and JTAG, network protocol analysis, and runtime exploitation to identify vulnerabilities across all layers of the IoT stack. Activates for requests involving IoT security testing, embedded device assessment, firmware security analysis, or smart device penetration testing.
ai-transparency-reqs
Implements AI transparency requirements under EU AI Act Arts. 13-14 and GDPR Arts. 13-14. Covers user notification of AI interaction, system capability disclosure, limitation documentation, and meaningful information about automated logic. Keywords: AI transparency, EU AI Act, GDPR notification, explainability, automated decision.
gdpr-prior-consultation
Guides the GDPR Article 36 prior consultation process with supervisory authorities when a DPIA indicates high residual risk. Covers timeline requirements, documentation, and outcome handling. Activate when DPIA residual risk remains high or when preparing regulatory submissions. Keywords: prior consultation, Article 36, DPIA, high risk, supervisory authority.
incident-log-analyzer
Analyze incident logs, extract error patterns, identify root causes, and generate insights and metrics. Use when a user mentions logs, incidents, errors, failures, debugging, troubleshooting, log analysis, or investigating production issues.
Smart Home Skill
Control smart home devices via IFTTT Webhooks.
filament-actions
Create FilamentPHP v4 actions with modals, confirmation, forms, and bulk operations
test-writer
TDD-focused test-writing skill for planning and implementing meaningful tests that verify behavior rather than implementation details. Activates on keywords like: test, unit test, write test, TDD, coverage, test case, spec.
sample-skill
Capability summary