跳到主要內容
fedi.software

代理技能

來自 skills.sh 目錄、適用於 Claude Code、Codex、Cursor 等代理的技能:安裝次數、安全稽核狀態,以及新增技能的指令。

技能不綁定單一代理:npx skills add 可安裝到任何支援的代理。不加 -a 時,CLI 會偵測電腦上的代理並詢問要加到哪裡。

更新日期 · 來源: skills.sh

顯示: 44 · 找到 44 個 · 目錄共 10,000 個

  • cloudflare cloudflare/skills

    Discover and choose Cloudflare products for apps, APIs, AI agents, storage, networking, and security. Use for architecture and product selection, including when the user describes a need without naming a Cloudflare product; then find the relevant skill or documentation.

    112,365 未通過
  • playwright-best-practices currents-dev/playwright-best-practices-skill

    Use when writing Playwright tests, fixing flaky tests, debugging failures, implementing Page Object Model, configuring CI/CD, optimizing performance, mocking APIs, handling authentication or OAuth, testing accessibility (axe-core), file uploads/downloads, date/time mocking, WebSockets, geolocation, permissions, multi-tab/popup flows, mobile/responsive layouts, touch gestures, GraphQL, error handling, offline mode, multi-user collaboration, third-party services (payments, email verification), console error monitoring, global setup/teardown, test annotations (skip, fixme, slow), test tags (@smoke, @fast, @critical, filtering with --grep), project dependencies, security testing (XSS, CSRF, auth), performance budgets (Web Vitals, Lighthouse), iframes, component testing, canvas/WebGL, service workers/PWA, test coverage, i18n/localization, Electron apps, or browser extension testing. Covers E2E, component, API, visual, accessibility, security, Electron, and extension testing.

    90,405 未通過
  • laravel-specialist jeffallan/claude-skills

    Build and configure Laravel 10+ applications, including creating Eloquent models and relationships, implementing Sanctum authentication, configuring Horizon queues, designing RESTful APIs with API resources, and building reactive interfaces with Livewire. Use when creating Laravel models, setting up queue workers, implementing Sanctum auth flows, building Livewire components, optimising Eloquent queries, or writing Pest/PHPUnit tests for Laravel features.

    22,491 未通過
  • security-review getsentry/skills

    Security code review for vulnerabilities. Use when asked to "security review", "find vulnerabilities", "check for security issues", "audit security", "OWASP review", or review code for injection, XSS, authentication, authorization, cryptography issues. Provides systematic review with confidence-based reporting.

    19,050 未通過
  • docker-patterns affaan-m/ecc

    Docker and Docker Compose patterns for local development, hardened CLI installer harnesses, container security, networking, volumes, and multi-service orchestration. Use when creating or reviewing Dockerfiles and Compose services, testing installers across Linux distributions, or planning accurate native macOS and Windows validation.

    12,664 未通過
  • penetration-testing-with-strix usestrix/strix

    Pentest a web app, API, codebase, repository, URL, domain, or IP with Strix — autonomous AI penetration testing that exploits and proves vulnerabilities (OWASP Top 10 and beyond — injection, XSS, SSRF, auth/access-control flaws, IDOR, business logic) instead of just flagging them. Runs self-hosted with the open-source CLI or via the managed app.strix.ai cloud, and returns validated findings with proof-of-concept exploits (Markdown, JSON, CSV, SARIF). Use when the user asks to pentest, hack, security-scan, security-audit, or find vulnerabilities in an app, API, website, or repo.

    12,151 未通過
  • laravel-security affaan-m/ecc

    Laravel security best practices — authentication, authorization, Eloquent safety, CSRF, XSS prevention, API security, and secure deployment configurations. Use when reviewing Laravel auth, Eloquent safety, CSRF, XSS, API security, or deployment configuration.

    10,715 未通過
  • security-scan affaan-m/ecc

    Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions. Use when auditing a .claude/ directory — CLAUDE.md, settings.json, MCP servers, hooks, or agent definitions.

    10,200 未通過
  • security-best-practices openai/skills

    Perform language and framework specific security best-practice reviews and suggest improvements. Trigger only when the user explicitly requests security best practices guidance, a security review/report, or secure-by-default coding help. Trigger only for supported languages (python, javascript/typescript, go). Do not trigger for general code review, debugging, or non-security tasks.

    9,961 未通過
  • wordpress-pro jeffallan/claude-skills

    Develops custom WordPress themes and plugins, creates and registers Gutenberg blocks and block patterns, configures WooCommerce stores, implements WordPress REST API endpoints, applies security hardening (nonces, sanitization, escaping, capability checks), and optimizes performance through caching and query tuning. Use when building WordPress themes, writing plugins, customizing Gutenberg blocks, extending WooCommerce, working with ACF, using the WordPress REST API, applying hooks and filters, or improving WordPress performance and security.

    9,201 未通過
  • spring-boot-engineer jeffallan/claude-skills

    Generates Spring Boot 3.x configurations, creates REST controllers, implements Spring Security 6 authentication flows, sets up Spring Data JPA repositories, and configures reactive WebFlux endpoints. Use when building Spring Boot 3.x applications, microservices, or reactive Java applications; invoke for Spring Data JPA, Spring Security 6, WebFlux, Spring Cloud integration, Java REST API design, or Microservices Java architecture.

    8,105 未通過
  • codeql trailofbits/skills

    Scans a codebase for security vulnerabilities using CodeQL's interprocedural data flow and taint tracking analysis. Triggers on "run codeql", "codeql scan", "build codeql database", "SAST scan", "taint analysis", "dataflow analysis", or "find vulnerabilities in this repo". Covers Python, JavaScript/TypeScript, Go, Java/Kotlin, C/C++, C#, Ruby, and Swift. Supports "run all" (security-and-quality + security-experimental) and "important only" (high-precision) scan modes, and creates data extension models for project-specific sources and sinks. For fast single-file pattern matching, or when no build is available for a compiled language, use the semgrep skill; to parse SARIF that already exists rather than produce it, use the sarif-parsing skill.

    7,755 未通過
  • ci-cd-security superagent-ai/skills

    Scan GitHub Actions workflow files for security vulnerabilities by reading the YAML and reporting findings directly — no external tools, no installation, no shell execution. Use this skill whenever the user shares a `.github/workflows/` file, pastes workflow YAML, asks for a CI/CD security review, mentions `pull_request_target`, `workflow_run`, action pinning, `GITHUB_TOKEN` permissions, pwn requests, template injection, cache poisoning, secret exfiltration, supply chain risk, or any GitHub Actions hardening topic. Also trigger when the user is hardening an OSS repo, doing a CI/CD red team assessment, evaluating a target for supply-chain scanning, or writing publicly about CI/CD security. Bias toward triggering this skill rather than answering from memory — CI/CD security defaults are wrong almost everywhere and the rules are unintuitive.

    7,302 未通過
  • code-reviewer jeffallan/claude-skills

    Analyzes code diffs and files to identify bugs, security vulnerabilities (SQL injection, XSS, insecure deserialization), code smells, N+1 queries, naming issues, and architectural concerns, then produces a structured review report with prioritized, actionable feedback. Use when reviewing pull requests, conducting code quality audits, identifying refactoring opportunities, or checking for security issues. Invoke for PR reviews, code quality checks, refactoring suggestions, review code, code quality. Complements specialized skills (security-reviewer, test-master) by providing broad-scope review across correctness, performance, maintainability, and test coverage in a single pass.

    6,072 未通過
  • network-config-validation affaan-m/ecc

    Pre-deployment checks for router and switch configuration, including dangerous commands, duplicate addresses, subnet overlaps, stale references, management-plane risk, and IOS-style security hygiene. Use when reviewing a router or switch configuration before deployment.

    5,712 未通過
  • security-reviewer jeffallan/claude-skills

    Identifies security vulnerabilities, generates structured audit reports with severity ratings, and provides actionable remediation guidance. Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews, dependency audits, secrets scanning, or compliance checks. Produces vulnerability reports, prioritized recommendations, and compliance checklists.

    5,560 未通過
  • fullstack-guardian jeffallan/claude-skills

    Builds security-focused full-stack web applications by implementing integrated frontend and backend components with layered security at every level. Covers the complete stack from database to UI, enforcing auth, input validation, output encoding, and parameterized queries across all layers. Use when implementing features across frontend and backend, building REST APIs with corresponding UI, connecting frontend components to backend endpoints, creating end-to-end data flows from database to UI, or implementing CRUD operations with UI forms. Distinct from frontend-only, backend-only, or API-only skills in that it simultaneously addresses all three perspectives—Frontend, Backend, and Security—within a single implementation workflow. Invoke for full-stack feature work, web app development, authenticated API routes with views, microservices, real-time features, monorepo architecture, or technology selection decisions.

    5,197 未通過
  • test-master jeffallan/claude-skills

    Generates test files, creates mocking strategies, analyzes code coverage, designs test architectures, and produces test plans and defect reports across functional, performance, and security testing disciplines. Use when writing unit tests, integration tests, or E2E tests; creating test strategies or automation frameworks; analyzing coverage gaps; performance testing with k6 or Artillery; security testing with OWASP methods; debugging flaky tests; or working on QA, regression, test automation, quality gates, shift-left testing, or test maintenance.

    4,935 未通過
  • substrate-vulnerability-scanner trailofbits/skills

    Scans Substrate/Polkadot pallets for 7 critical vulnerabilities including arithmetic overflow, panic DoS, incorrect weights, and bad origin checks. Use when auditing Substrate runtimes or FRAME pallets.

    4,819 未通過
  • ghost-scan-code ghostsecurity/skills

    Ghost Security - SAST code scanner. Finds security vulnerabilities in source code by planning and executing targeted scans for issues like SQL injection, XSS, BOLA, BFLA, SSRF, and other OWASP categories. Supports applications (backend, frontend, mobile) and libraries (prototype pollution, unsafe deserialization, ReDoS, path traversal, zip slip). Use when the user asks for a code security audit, SAST scan, vulnerability scan of source code, or wants to find security flaws in a codebase or library.

    4,785 未通過
  • secure-code-guardian jeffallan/claude-skills

    Use when implementing authentication/authorization, securing user input, or preventing OWASP Top 10 vulnerabilities — including custom security implementations such as hashing passwords with bcrypt/argon2, sanitizing SQL queries with parameterized statements, configuring CORS/CSP headers, validating input with Zod, and setting up JWT tokens. Invoke for authentication, authorization, input validation, encryption, OWASP Top 10 prevention, secure session management, and security hardening. For pre-built OAuth/SSO integrations or standalone security audits, consider a more specialized skill.

    4,715 未通過
  • gha-security-review getsentry/skills

    GitHub Actions security review for workflow exploitation vulnerabilities. Use when asked to "review GitHub Actions", "audit workflows", "check CI security", "GHA security", "workflow security review", or review .github/workflows/ for pwn requests, expression injection, credential theft, and supply chain attacks. Exploitation-focused with concrete PoC scenarios.

    4,555 未通過
  • security-case-management elastic/agent-skills

    3,752 未通過
  • security-ownership-map openai/skills

    Analyze git repositories to build a security ownership topology (people-to-file), compute bus factor and sensitive-code ownership, and export CSV/JSON for graph databases and visualization. Trigger only when the user explicitly wants a security-oriented ownership or bus-factor analysis grounded in git history (for example: orphaned sensitive code, security maintainers, CODEOWNERS reality checks for risk, sensitive hotspots, or ownership clusters). Do not trigger for general maintainer lists or non-security ownership questions.

    3,566 未通過
  • business-logic-vulnerabilities yaklang/hack-skills

    Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.

    3,564 未通過
  • skill-scanner getsentry/skills

    Scan agent skills for security issues. Use when asked to "scan a skill",

    3,490 未通過
  • security-alert-triage elastic/agent-skills

    3,476 未通過
  • security-detection-rule-management elastic/agent-skills

    3,459 未通過
  • security-generate-security-sample-data elastic/agent-skills

    3,411 未通過
  • ai-ml-security yaklang/hack-skills

    AI/ML security playbook. Use when assessing model supply chain attacks (pickle RCE, poisoned weights), adversarial examples, model poisoning, model stealing, data privacy attacks (membership inference, model inversion), and autonomous agent security risks.

    3,268 未通過
  • vibe-security raroque/vibe-security-skill

    Audits codebases for common security vulnerabilities that AI coding assistants introduce in "vibe-coded" applications. Checks for exposed API keys, broken access control (Supabase RLS, Firebase rules), missing auth validation, client-side trust issues, insecure payment flows, and more. Use this skill whenever the user asks about security, wants a code review, mentions "vibe coding", or when you're writing or reviewing code that handles authentication, payments, database access, API keys, secrets, or user data — even if they don't explicitly mention security. Also trigger when the user says things like "is this safe?", "check my code", "audit this", "review for vulnerabilities", or "can someone hack this?".

    3,249 未通過
  • linux-security-bypass yaklang/hack-skills

    Linux security mechanism bypass playbook. Use when facing restricted bash/rbash, read-only or noexec filesystems, AppArmor, SELinux, seccomp filters, or audit logging that must be evaded during post-exploitation.

    3,242 未通過
  • ntlm-relay-coercion yaklang/hack-skills

    NTLM relay and authentication coercion playbook. Use when capturing and relaying NTLM authentication to escalate privileges via SMB, LDAP, HTTP, or MSSQL relay targets, combined with PetitPotam, PrinterBug, and other coercion methods.

    3,193 未通過
  • elasticsearch-security-troubleshooting elastic/agent-skills

    2,909 未通過
  • openclaw-config adisinghstudent/ara.so

    Manage OpenClaw bot configuration - channels, agents, security, and autopilot settings

    2,836 未通過
  • okx starchild-ai-agent/official-skills

    OKX OnChainOS: on-chain trading, analytics, security, DeFi across 20+ chains. Use when running OKX-routed on-chain ops (e.g. swap on Ethereum, scan token risk, track smart money, check wallet portfolio). Wallet: default to the user's Agent Wallet (via the `wallet` skill). Only use the OnchainOS TEE wallet (`onchainos wallet login <email>`) when the user explicitly asks for it.

    1,652 未通過
  • adk-frontend botpress/skills

    Guidelines for building frontend applications that integrate with Botpress ADK bots - covering authentication, type generation, client setup, and calling bot actions

    1,612 未通過
  • llm-security semgrep/skills

    Security guidelines for LLM applications based on OWASP Top 10 for LLM 2025. Use when building LLM apps, reviewing AI security, implementing RAG systems, or asking about LLM vulnerabilities like 'prompt injection' or 'check LLM security'. IMPORTANT: Always consult this skill when building chatbots, AI agents, RAG pipelines, tool-using LLMs, agentic systems, or any application that calls an LLM API (OpenAI, Anthropic, Gemini, etc.) — even if the user doesn't explicitly mention security. Also use when users import 'openai', 'anthropic', 'langchain', 'llamaindex', or similar LLM libraries.

    1,462 未通過
  • gws-shared streakyc/googleworkspacecli

    gws CLI: Shared patterns for authentication, global flags, and output formatting.

    1,408 未通過
  • security boshu2/agentops

    Review code or scan for security vulnerabilities, secrets, dependencies and prompt risks. Use when: concrete exposure needs assessment; never silently change policy.

    1,398 未通過
  • cybersecurity-analyst rysweet/amplihack

    Analyzes events through cybersecurity lens using threat modeling, attack surface analysis, defense-in-depth, zero-trust architecture, and risk-based frameworks (CIA triad, STRIDE, MITRE ATT&CK). Provides insights on vulnerabilities, attack vectors, defense strategies, incident response, and security posture. Use when: Security incidents, vulnerability assessments, threat analysis, security architecture, compliance. Evaluates: Confidentiality, integrity, availability, threat actors, attack patterns, controls, residual risk.

    1,398 未通過
  • openclaw-config reason-machines/trending-skills

    Manage OpenClaw bot configuration - channels, agents, security, and autopilot settings

    1,385 未通過
  • pentest-ai-agents reason-machines/security-skills

    Claude Code subagents for offensive security research, penetration testing planning, recon analysis, exploit research, detection engineering, and security reporting

    1,331 未通過
  • pentest-tools zhaoxuya520/reverse-skill

    主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。

    1,327 未通過

說明文字由作者本人以英文撰寫。安裝前請先到儲存庫閱讀技能的程式碼。

技能是給 AI 代理使用的擴充,例如 Claude Code、Codex、Cursor 等。一個技能就是一個資料夾,裡面有 SKILL.md 檔案,也可能附上腳本;當任務符合描述時,代理會載入它。這樣代理就能取得特定工作的指引,例如製作文件、撰寫測試或使用某個框架。

目錄裡有什麼

目錄收錄 skills.sh 上的技能,顯示名稱、作者與儲存庫、安裝數、「安全稽核」狀態,以及加入技能的指令與「複製指令」按鈕。收錄依安裝數排名的前 10,000 個技能,每天同步。「熱門趨勢」依過去 7 天新增的安裝數排序。每次顯示最多 100 個技能,可以用主題、代理篩選或搜尋找到更多。

如何安裝技能

  1. 依主題或您使用的代理找出技能。
  2. 查看稽核狀態:「通過」、「有警告」、「未通過」或「未稽核」。
  3. 打開儲存庫,閱讀程式碼與 SKILL.md。
  4. 按「複製指令」,在專案資料夾中執行。

安全

稽核通過並不是保證。技能可能包含代理會在您電腦上執行的腳本,安裝前請先讀過儲存庫中的程式碼,安裝數少或未稽核的技能更要小心。稽核狀態與安裝數都來自 skills.sh。

英文說明

技能說明由作者撰寫,使用英文,我們不做翻譯,因為代理讀的是原文。挑選代理請看 程式設計代理,背後的模型請看 代理排行榜。已安裝的技能也要定期檢查,移除用不到的,避免代理載入多餘的指引。

來源:skills.sh(目錄、安裝數、稽核)與 GitHub(各技能的程式碼)。