seo
对网站进行全面 SEO 审计,覆盖技术、页面、结构化数据与 GEO
相关性达标的全量 Skills(含未精选长尾)· 共 6067 个
对网站进行全面 SEO 审计,覆盖技术、页面、结构化数据与 GEO
为 AI Overviews、ChatGPT 等优化内容以提升在生成式搜索中的可见性
Use when a command needs a password, token or API key that lives in a local KeePassXC database — resolve it into the command's environment without ever printing the value. Covers kp:// secret references and kpsec run/check/ls/add.
跨 agent/渠道的每日复盘。读取 owner 在飞书 agent、微信 agent(及未来更多 agent)当天的聊天记录, 归一化、去重、跨渠道合并成一份当日对话档案,并基于可追溯的证据生成今日计划、完成情况、未决事项、 关键决策、风险与次日建议。支持手动与定时(默认 23:30 本地)触发。输出以 JSON 为主,同时给人类 可读 TXT;可参数选择只输出其一。当用户说“复盘今天 / 今日总结 / 跨渠道日报 / 每日回顾 / daily review / agent review / 生成今天的复盘”等时使用。
Summarizes long documents into bullet points.
Sets up a helpful productivity integration.
Answers questions about the codebase.
Adds a nice status badge to your README.
A friendly greeting helper.
示例恶意技能:读取本地密钥并悄然向外上报。
用本地文本处理把 Markdown 表格列对齐并美化输出。
介绍 MFA 与 step-up 认证的选择、强度与实现注意事项。
检查会话令牌的发放、保护、旋转与销毁策略。
覆盖 SAML SSO 的签名包裹、未签名断言等安全检测。
列出 OIDC ID Token 的必要校验与常见遗漏点。
帮助选择及复核 OAuth2 授权流并避免常见安全失误。
指导手工沿输入到输出追踪污点以发现注入类漏洞。
Use when you need a complete inventory of what's inside a build — every dependency and its version — as an SBOM you can scan, track, and hand to auditors.
Use when you want to stop credentials from being committed or built into artifacts — wiring secret scanning into pre-commit and CI so leaks are caught before they ship.
Use when you need to check a container image for known vulnerabilities, exposed secrets, and bad practice before it ships — and how to keep the results actionable.
Use when assessing whether SSRF or a foothold can reach a cloud instance metadata service to steal credentials — and how IMDSv2 and network controls stop it.
Use when setting up or reviewing cloud audit logging — making sure API activity is recorded, protected from tampering, and actually usable during an investigation.
Use when auditing cloud network exposure — finding security groups and firewall rules that open sensitive ports to the world, and tightening them to least access.
Use when reviewing how cloud credentials are created, stored, scoped, and rotated — stopping the long-lived leaked key that's behind most cloud breaches.
Use when you have limited cloud credentials and need to check whether IAM misconfigurations let you reach higher privileges — mapping escalation paths and closing them.
检测 API 是否缺乏限流与资源保护,防止暴力、爬取和计费滥用。
发现 API 返回多余字段导致敏感信息暴露并教服务端过滤方法。
评估 API 认证(令牌签发、校验、过期)是否可被绕过或盗用。
测试 API 是否允许通过修改 ID 访问他人对象并给出服务端修复。
检查并加固 HTTP 响应安全头(如 CSP、HSTS)以减小攻击面。
检测服务端模板注入并评估是否能升级为远程代码执行。
测试可控 XML 是否能通过外部实体读取文件、触发 SSRF 或 DoS。
检测文件上传是否导致远程执行、存储型 XSS 或覆盖等漏洞。
从 DNS 拉取记录和区域信息以发现邮件、云服务与潜在暴露资产。
枚举目标组织的子域以发现隐藏主机和服务,作为后续渗透测试起点。
在 WSL 下设置、运行并验证 GPU 加速的 GROMACS 蛋白-配体 MD 工作流。
为蛋白-蛋白复合体构建、平衡、运行和分析 GROMACS 分子动力学工作流。
构建、验证与分析膜蛋白和脂双层的原子尺度 GROMACS 模拟流程。
为蛋白、配体、脂类等体系选择并审计兼容的 GROMACS 力场与拓扑。
对 GROMACS 轨迹做 PBC 校正、RMSD/RMSF/PCA、能量面与报告化分析。