DevOps & Security skills

Browse reusable Agent Skills, each with a clear purpose and practical guidance.

configuration-sso-app

caddy-security SSO app Caddyfile configuration for Single Sign-On with SAML. Use when creating, reviewing, or modifying sso provider blocks, AWS SAML app drivers, SAML entity IDs, signing certificates, PKCS8 private keys, SSO metadata locations, authentication portal enablement, /apps/sso endpoints, and AWS role naming.

2.19k repo starsObserved in 1 repos
DevOps & Security

configuration-users

caddy-security local user account Caddyfile configuration. Use when creating, reviewing, or modifying local identity store user entries, usernames, display names, email addresses, plaintext or bcrypt passwords, overwrite behavior, roles, static API key prefixes and payloads, and secret-backed user attributes.

2.19k repo starsObserved in 1 repos
DevOps & Security

scripts-and-automation

caddy-security repository automation, Makefile target selection, local build/test/report/coverage commands, local go-authcrunch go.mod replacement shim workflow, asset and documentation update scripts, release/version workflows, generated artifact handling, and guardrails for dependency, devbuild, cleanup, and release actions. Use when choosing, running, documenting, or updating repository scripts and Make targets; troubleshooting CI/build/test automation; coordinating caddy-security development with local go-authcrunch changes; refreshing Caddyfile/config fixtures; deciding whether generated outputs belong in a change; or preparing releases for this Go/Caddy module.

2.19k repo starsObserved in 1 repos
DevOps & Security

dstack

dstack is an open-source control plane for GPU provisioning and orchestration across GPU clouds, Kubernetes, and on-prem clusters.

2.19k repo starsObserved in 2 repos
DevOps & Security

miniapp-security-core

Use when reviewing authorized WeChat mini-program or mini-app targets for authentication bypass, IDOR, undefined-path access, API abuse, decryption and signature analysis, runtime reverse engineering, route mapping, and sensitive data exposure, with file-submission attack surfaces intentionally excluded.

2.18k repo starsObserved in 1 repos
DevOps & Security

redact-pii

Redact personal data from a document through the connected Superlinked MCP edge before working with the content. Use when the user asks to redact, anonymize, scrub, de-identify, or remove PII/sensitive data from a document.

2.17k repo starsObserved in 1 repos
DevOps & Security

selfmonitor

自监控指标、告警代码标准

2.16k repo starsObserved in 1 repos
DevOps & Security

f8x-tool-maintenance

维护 f8x 渗透工具安装器:新增工具安装函数、更新版本号、管理 F8X_TOOL_LIST 注册、构建 Arsenal 多平台投递物。当修改 f8x 脚本、添加新渗透工具、更新工具版本、检查工具覆盖、或构建 arsenal 二进制时,务必使用此 skill。即使用户只是提到 "装个 xxx 工具"、"f8x 里加一下"、"更新一下版本" 也应触发。

2.15k repo starsObserved in 1 repos
DevOps & Security

f8x-version-update

批量检查和更新 f8x 中工具的版本号。当需要检查哪些工具有新版本、更新某个工具的版本、或批量更新版本时使用。即使用户只是说 "检查一下版本"、"xxx 更新了没"、"升级一下工具" 也应触发。

2.15k repo starsObserved in 1 repos
DevOps & Security

jar-audit-agent

基于 jar-analyzer(SQLite + 内置 MCP)的证据驱动 Java 安全审计技能。核心目标:把“结论”变成“可复现证据 + 可度量覆盖率”。

2.13k repo starsObserved in 1 repos
DevOps & Security