Browse Skills
841 skills across 8 categories
✏️
1w ago
Huashu Article Editor
Provides a standardized article editing workflow that ensures clear modification scopes, trackable progress, and documented changes. Use when requesting edits, modifications, or adjustments to existing articles.
Writing
+2%1.3K209
🐝
1w ago
Agent Swarm
Orchestrate multiple AI agents working in parallel on a large project using git-based self-organization. Each agent autonomously picks tasks, writes code, and pushes via git worktrees.
AI Engineering
+2%1.3K209
🎬
2w ago
Douyin Viral Script Creator
Creates viral Douyin video scripts by downloading competitor videos, analyzing them with Gemini, extracting successful patterns, generating scripts and storyboards, and proofreading for a human-like tone.
Writing
+2%1.3K209
🔍
1w ago
Path Traversal Detection
Detect path traversal vulnerabilities in a codebase using a three-phase approach: recon, batched verification, and merge. Use for finding directory traversal, path traversal, or file disclosure bugs.
Quality
+1%1.2K60
🔒
1w ago
Missing Auth Detection
Detect missing authentication and broken function-level authorization vulnerabilities in a codebase using a three-phase approach. Covers unauthenticated access and vertical privilege escalation. Use when asked to find missing auth, broken access control, or privilege escalation bugs.
Quality
+1%1.2K60
🔐
1w ago
JWT Vulnerability Detection
A two-phase SAST skill that maps all JWT issuance and verification sites in a codebase, then checks for exploitable weaknesses like algorithm confusion, weak secrets, and missing signature verification. Use to find JWT forgery or authentication bypass bugs.
AI Engineering
+1%1.2K60
🔑
1w ago
Hardcoded Secrets Detection
Detects hardcoded sensitive data (API keys, tokens, passwords) in publicly accessible code like frontend JavaScript, mobile apps, and HTML templates. Uses a three-phase approach: recon, batched verification, and merge. Requires prior architecture analysis.
Quality
+1%1.2K60
🛡️
1w ago
GraphQL Injection Detection
Detect GraphQL injection vulnerabilities in a codebase using a three-phase approach: recon, batched verify, and merge. Requires sast/architecture.md first; outputs to sast/graphql-results.md.
Quality
+1%1.2K60
🔍
1w ago
Insecure File Upload Detection
Detects insecure file upload vulnerabilities using a three-phase approach: discovery of upload endpoints, batched verification of extension bypasses via parallel subagents, and result merging. Use for finding file upload, extension bypass, or unrestricted upload bugs.
Quality
+1%1.2K60
🔍
1w ago
Business Logic Vulnerability Detection
Analyzes codebases for business logic vulnerabilities using a three-phase approach: threat modeling, batched verification, and merge. Covers price manipulation, workflow bypass, race conditions, reward abuse, and more. Requires an architecture document; outputs findings to a results file.
Quality
+1%1.2K60
🔍
1w ago
SAST Analysis
Performs codebase reconnaissance and architecture mapping for security assessments. Identifies technology stack, entry points, data flows, and trust boundaries. Outputs a structured architecture.md to guide subsequent vulnerability detection.
AI Engineering
+1%1.2K60
🛡️
1w ago
XXE Vulnerability Detection
Detects XML External Entity (XXE) vulnerabilities in codebases using a three-phase SAST approach. Use when asked to find XXE or XML injection bugs.
Quality
+1%1.2K60