trivy-vulnerability-scanning
cxcscmu
Use Trivy vulnerability scanner in offline mode to detect CVEs in npm dependencies and generate structured JSON reports.
OPENAGENTSKILL / DIRECTORY
Find a skill for your next task. Explore tools for Codex, Claude Code, Cursor and more.
Find a skill for your next task. Preview examples where available.
Page 71 · 16 shown · 1,228 public entries
Results: 1228
cxcscmu
Use Trivy vulnerability scanner in offline mode to detect CVEs in npm dependencies and generate structured JSON reports.
zhaji2333
当目标存在REST/GraphQL/gRPC/WebSocket接口、Swagger/OpenAPI文档、调试端点(actuator/console)、旧版本API、内部接口、微服务网关,或需要测试HTTP走私、DoS、速率限制时调用。负责API全方法测试、BOLA越权、GraphQL深度攻击、协议层漏洞挖掘。
zhaji2333
当需要获取目标 APK、识别加固壳类型、脱壳还原 dex、反编译得到 Java/so/H5 全量源码产物,或 android-security-audit 需要可直接开挖的输入时调用。负责 APK → 全量可审计产物(壳识别 → 脱壳 → JADX 反编译 + apktool 资源 + so 提取 + H5/assets 提取)→ 标准…
zhaji2333
当目标为微信/支付宝/抖音/百度等小程序(含微信云开发/云函数)、需要小程序包获取与反编译、appid/appsecret/接口提取、微信登录链/支付/越权/WebView/rich-text 渲染/云开发漏洞挖掘时调用。负责小程序全生命周期深度挖掘:包还原 → 代码审计 → 接口与密钥提取 → 登录/支付/越权/渲染/云开发专项 →…
LazyAGI
Review frontend and UI changes for concrete security risks such as XSS, unsafe URL handling, token leakage, missing origin checks, and client-side authorization gaps. Us…
Junhanliu-dev
Migrate an existing harness/espalier install to the current Espalier version — auto-detects which of v0.1→v0.2, v0.3→v0.4, v0.4→v0.5, the v0.5.3 coder-agent patch, v0.5→…
eduardo-sl
Comprehensive code review checklist for Go projects. Evaluates code quality, idiomatic patterns, error handling, naming, package structure, and test coverage. Use when r…
eduardo-sl
Prevent panics, silent corruption, and subtle runtime bugs in Go: typed-nil interfaces, slice aliasing, integer overflow on conversion, float comparison, defer in loops,…
eduardo-sl
gRPC services in Go beyond the basics: proto design, status codes and error details, interceptors, deadlines, streaming, health checks, and graceful shutdown. Use when:…
Security-Phoenix-demo
Role 05 of the Phoenix Security spec pipeline. Red-teams normative requirements for Phoenix-specific failure modes: multi-tenant isolation gaps, vague integration surfac…
Security-Phoenix-demo
Role 09 of the Phoenix Security spec pipeline. Slices a Phoenix Security feature into safe, incremental batches sized for a 12-person team (1–3 engineer-days each), with…
Security-Phoenix-demo
Role 03 of the Phoenix Security spec pipeline. Distils SCOPE_DEFINITION into an ACTIVE_SET of 8–15 compact, testable constraints that govern all downstream requirements…
Security-Phoenix-demo
Role 01 of the Phoenix Security spec pipeline. Cleans raw input — notes, tickets, Slack threads, customer call transcripts — into a structured CLEAN_CONTEXT block of FAC…
Security-Phoenix-demo
Role 07 of the Phoenix Security spec pipeline. Turns Phoenix Security requirements into precise implementable contracts: REST API endpoints with Phoenix auth patterns, t…
Security-Phoenix-demo
Role 10 of the Phoenix Security spec pipeline. Makes the final SHIP / NO_SHIP decision for a Phoenix Security feature spec by checking 8 hard blockers: critical ambiguit…
Security-Phoenix-demo
Interactive guide and launcher for the Phoenix Security spec pipeline. Asks where you are in the process, what you want to do next, and routes you to the right skill wit…