编程 AI 技能

4,536 个编程任务的工具和技能

想查看每个技能的完整信息?

通过 GitHub 登录即可解锁作者信息、星标数量、源码链接等更多详情。

使用 GitHub 登录

bug-bounty

Complete bug bounty workflow — recon (subdomain enumeration, asset discovery, fingerprinting, HackerOne scope, source code audit), pre-hunt learning (disclosed reports, tech stack research, mind maps, threat modeling), vulnerability hunting (IDOR, SSRF, XSS, auth bypass, CSRF, race conditions, SQLi, XXE, file upload, business logic, GraphQL, HTTP smuggling, cache poisoning, OAuth, timing side-channels, OIDC, SSTI, subdomain takeover, cloud misconfig, ATO chains, agentic AI), LLM/AI security testing (chatbot IDOR, prompt injection, indirect injection, ASCII smuggling, exfil channels, RCE via code tools, system prompt extraction, ASI01-ASI10), A-to-B bug chaining (IDOR→auth bypass, SSRF→cloud metadata, XSS→ATO, open redirect→OAuth theft, S3→bundle→secret→OAuth), bypass tables (SSRF IP bypass, open redirect bypass, file upload bypass), language-specific grep (JS prototype pollution, Python pickle, PHP type juggling, Go template.HTML, Ruby YAML.load, Rust unwrap), and reporting (7-Question Gate, 4 validation gates, human-tone writing, templates by vuln class, CVSS 3.1, PoC generation, always-rejected list, conditional chain table, submission checklist). Use for ANY bug bounty task — starting a new target, doing recon, hunting specific vulns, auditing source code, testing AI features, validating findings, or writing reports. 中文触发词:漏洞赏金、安全测试、渗透测试、漏洞挖掘、信息收集、子域名枚举、XSS测试、SQL注入、SSRF、安全审计、漏洞报告

作者

debug-assist

This skill should be used when the user needs to diagnose a bug, wants to add debug logging or print statements, asks where to place logging, wants guidance on step-through debugging or breakpoints, needs to know what variables or state to inspect, asks about managing temporary debug code before committing, wants to clean up debug statements, or says things like "I can't figure out why this is failing", "help me debug this", "add some logging here", or "where should I put a breakpoint". Applies to any language or platform.

作者

kata

"Kata — a self-evolving knowledge system for AI-paired builders. CORE: self-closing wiki loop + auto-dreaming on Karpathy's LLM-Wiki principle. Phase 1 (current): AI-paired engineering — compile project business semantics so agents read project conventions before they write code. Phase 2 (designed): team spec authoring + dispute resolution. 17 skills (init / import / ingest / search / graph / tier / digest / query / lint / config / dream / watch / sync / spec / session-ingest / mcp-server / federate). v1.13 SHM Phase 0+2. v1.11 session-ingest MVP. **v1.12 cross-wiki federation complete (Phase 0+1+2+3)**: kata is both MCP server + client; parallel fan-out; kata:// URI with name/wiki_id forms; wiki_id identity check; federated spec preflight with cross-wiki enforcement."

作者

brainstorming-pro

"Use before non-trivial product, UX, or architecture design work when requirements are still evolving and implementation should be preceded by design alignment. Clarifies intent, constraints, trade-offs, and writes an approved spec before implementation. Trigger for requests like designing a new feature, defining a user flow, planning component behavior across screens, or shaping a broad behavior change with multiple valid approaches. Do not use for bug fixes, small refactors, targeted copy edits, tests, docs, dependency bumps, metadata tweaks, or straightforward config changes with clear requirements."

作者

rust-api-guidelines

Use when the agent must read, apply, or review against the official Rust API Guidelines from rust-lang.github.io and must fetch the live pages first instead of relying on memory or local copies. Trigger this skill for Rust API design reviews, crate audits, naming checks, documentation checks, macro guidance, predictability and flexibility reviews, type-safety and dependability reviews, debuggability and future-proofing checks, or any request to consult the Rust API Guidelines online.

作者

« 上一页第 4 页,共 91 页下一页 »