发现 Skills
为真实工作流程挑选经过整理的 Skill,连接、安装并开始使用。
detect-mcp-plugin-supply-chain
Detect MCP server tools/list responses where any tool's inputSchema references a hostname not in MCP_PLUGIN_ALLOWED_HOSTS. Reads OCSF 1.8 Application Activity (class 6002) records produced by ingest-mcp-proxy-ocsf and walks the tool's JSON schema (oneOf / anyOf / allOf / properties / items / $ref / default / description) extracting every URL-shaped string. Fires once per (session, host) pair when the host falls outside the allowlist. Maps to OWASP LLM Top 10 LLM05 Supply Chain via Plugins/Tools. Use when the user mentions MCP plugin supply chain, untrusted schema $ref, LLM05, or tool inputSchema fetching remote definitions. Do NOT use on raw MCP proxy logs — feed them through ingest-mcp-proxy-ocsf first. Do NOT use as a generic URL scanner; the contract is scoped to inputSchema URLs in tools/list responses.
detect-web-broken-access-control
Detect OWASP Top 10 A01:2021 (Broken Access Control) signals in HTTP access logs. Reads OCSF 1.8 HTTP Activity (class 4002) records and fires when one of two deterministic patterns appears: (1) the resource path embeds a user / account / object id that does not match the actor's authenticated subject claim (IDOR — horizontal privilege escalation), or (2) a 4XX response from one principal is followed inside a short window by a 2XX response on the exact same URL after an Authorization header swap (the "auth-swap flip" — typical privilege bypass via stolen / forged token). Emits OCSF Detection Finding 2004 tagged OWASP A01 + MITRE ATT&CK T1212. Use when an ingestion pipeline normalizes web-server / WAF / API-gateway logs into OCSF 4002 and you want a deterministic, no-LLM authz-violation detector. Do NOT use as a WAF, as a posture check on IAM policies (different surface — see CSPM benchmarks), for service-mesh L7 authorisation (Envoy / Istio emit a different log shape), or as a substitute for application-layer authorization tests in CI.
inbox-triage
Process raw Todoist inbox items into a structured knowledge system using GTD (actions → Todoist) and PARA (reference → Obsidian). Use this skill whenever the user says "process my inbox", "triage my todoist", "clean up inbox items", "file these captures", or has a batch of raw items (voice notes, links, ideas) that need classifying and filing. Also use when the user mentions inbox zero, PARA filing, or batch-processing captures into Obsidian notes — even if they don't explicitly say "triage".
crosspost
Multi-platform content distribution across X, LinkedIn, Threads, and Bluesky. Adapts content per platform using content-engine patterns. Never posts identical content cross-platform. Use when the user wants to distribute content across social platforms.
hipaa-compliance
HIPAA-compliant implementations, security controls, audit logging, and data protection strategies.
homelab-pihole-dns
Pi-hole DNS configuration for homelab: ad blocking, privacy, and custom domain resolution.
openspec-sync-specs
Sync delta specs from a change to main specs. Use when the user wants to update main specs with changes from a delta spec, without archiving the change.
code-reviewer
Review code for bugs, logic errors, security vulnerabilities, code quality issues, and adherence to project conventions, using confidence-based filtering to report only high-priority issues that truly matter. Use this skill when reviewing a small set of changes locally (such as unstaged diff), when dispatched as a sub-task during feature-dev quality review, or when the user wants a critique of a specific file or function.
profile-report
Unified personal genomic profile report — reads a PatientProfile JSON and synthesizes all skill results into a single "Your Genomic Profile" document.
variant-annotation
Annotate VCF variants with Ensembl VEP REST, ClinVar significance, gnomAD/population frequency context, and prioritized variant ranking.
opence-archive
Archive a completed change and apply spec updates to the main specifications.
opence-plan
Create an opence plan and scaffold change artifacts.
hunting-for-persistence-mechanisms-in-windows
Systematically hunt for adversary persistence mechanisms across Windows endpoints including registry, services, startup folders, and WMI subscriptions.
performing-directory-traversal-testing
Testing web applications for path traversal vulnerabilities that allow reading or writing arbitrary files on the server by manipulating file path parameters.
performing-privileged-account-access-review
Conduct systematic reviews of privileged accounts to validate access rights, identify excessive permissions, and enforce least privilege across PAM infrastructure.
securing-container-registry-images
Securing container registry images by implementing vulnerability scanning with Trivy and Grype, enforcing image signing with Cosign and Sigstore, configuring registry access controls, and building CI/CD pipelines that prevent deploying unscanned or unsigned images.
detecting-privilege-escalation-attempts
Detect privilege escalation attempts including token manipulation, UAC bypass, unquoted service paths, kernel exploits, and sudo/doas abuse across Windows and Linux.
implementing-file-integrity-monitoring-with-aide
Configure AIDE (Advanced Intrusion Detection Environment) for file integrity monitoring including baseline creation, scheduled integrity checks, change detection, and alerting
managing-mobile-app-consent
Guide for mobile-specific consent management covering Apple ATT framework for iOS, Android permission model, in-app consent flows, SDK consent propagation to third-party libraries, and IDFA/GAID handling. Addresses platform-specific requirements alongside GDPR and ePrivacy compliance for mobile applications.
state-law-applicability
US state privacy law applicability assessment tool. Evaluates revenue thresholds, data volume thresholds, business exemptions (GLBA, HIPAA, nonprofits), employee data carve-outs, and SBA small business determinations across all enacted state privacy laws.
uk-aadc-implementation
Implements the UK Age Appropriate Design Code (Children's Code) 15 standards under the Data Protection Act 2018 Section 123. Covers best interests assessment, age-appropriate application, transparency, data minimization, geolocation restrictions, and profiling defaults. Keywords: AADC, Children's Code, ICO, age appropriate design, UK.
CORE
Qara (Personal AI Infrastructure) - Jean-Marc Giorgi's AI System. Loads automatically at session start. Provides identity, operating principles, workflow routing, stack preferences, and security protocols. USE WHEN: Always active - core system identity and behavior.
codex-validate-plan
Validate architecture and plan quality via claude-delegator (Plan Reviewer expert). Use this after authoring or updating context.md for complex feature or refactor work.
outlook-calendar
Manage Outlook calendar via PowerShell: list events, create/update/delete appointments, send meeting invites, respond to meetings, recurring events, check availability, and find rooms. Scripts auto-start Outlook when needed.