🔒

測試與安全

測試框架、安全工具和最佳實踐

9063 skills in this category

python-coding-standards

Python coding standards following PEP 8, type hints, testing best practices, and modern Python patterns. Use for Python projects requiring clean, maintainable, production-ready code with comprehensive testing.

williamzujkowski/standards
11
0
更新於 1w ago

service-mesh

A service mesh is an infrastructure layer that provides transparent service-to-service communication with built-in observability, traffic management, and security features without requiring application code changes.

williamzujkowski/standards
11
0
更新於 1w ago

deployment-sop

Deployment workflows, pre-deploy validation, and smoke testing patterns. Use when deploying to staging or production, running smoke tests, or validating deployments.

bybren-llc/wtfb-safe-agentic-workflow
11
4
更新於 1w ago

Debugging and Troubleshooting

Marketplace

Systematic error diagnosis and debugging workflow for Rust code. Use when code isn't working, tests fail, or runtime errors occur.

ShunsukeHayashi/Miyabi
11
6
更新於 1w ago

e2e-testing-standards

Implement robust E2E tests with Playwright or Cypress using Page Object Model, proper waits, and CI/CD integration. Covers selector strategies, flaky test prevention, and cross-browser testing patterns.

williamzujkowski/standards
11
0
更新於 1w ago

unit-testing

Unit testing standards following TDD methodology, test pyramid principles, and comprehensive coverage practices. Covers pytest, Jest, mocking, fixtures, and CI integration for reliable test suites.

williamzujkowski/standards
11
0
更新於 1w ago

setup-tester

Test and validate the dotfiles setup process for this repository. Use when the user wants to test the setup script, validate the installation, verify symlinks, troubleshoot setup issues, or check that dotfiles are properly configured. Triggers include "test setup", "validate installation", "check dotfiles", "verify setup", or troubleshooting requests.

ruchernchong/dotfiles
11
2
更新於 1w ago

test-generator

Marketplace

Generate comprehensive unit tests for code. Use when creating tests, improving test coverage, or setting up testing frameworks.

ShunsukeHayashi/Miyabi
11
6
更新於 1w ago

testing

Comprehensive testing standards including unit, integration, security, and property-based testing with TDD methodology

williamzujkowski/standards
11
0
更新於 1w ago

Security Audit and Vulnerability Scanning

Marketplace

Comprehensive security audit workflow including dependency scanning, unsafe code detection, and secret management. Use when scanning for vulnerabilities or before production deployment.

ShunsukeHayashi/Miyabi
11
6
更新於 1w ago

zero-trust-security

Zero-trust architecture operates on the principle: "Never trust, always verify." Unlike traditional perimeter-based security, zero-trust assumes breach and verifies every request regardless of origin.

williamzujkowski/standards
11
0
更新於 1w ago

lnd

Run and interact with lnd Lightning Network daemon in Docker. Use for Lightning development, testing payment channels on regtest, managing lnd containers, and calling lnd RPC endpoints (getinfo, connect, open/close channels, pay/receive). Supports bitcoind, btcd, and neutrino backends.

Roasbeef/claude-files
11
2
更新於 1w ago

github-pr-merge

Marketplace

Merges GitHub Pull Requests after validating pre-merge checklist. Use when user wants to merge PR, close PR, finalize PR, complete merge, approve and merge, or execute merge. Runs pre-merge validation (tests, lint, CI, comments), confirms with user, merges with proper format, handles post-merge cleanup.

fvadicamo/dev-agent-skills
11
1
更新於 1w ago

systematic-debugging

Marketplace

Use when debugging bugs, test failures, unexpected behavior, or needing to find root cause before fixing

TechNickAI/ai-coding-config
11
1
更新於 1w ago

api-security

1. Broken Object Level Authorization (BOLA) - API fails to validate user access to objects 2. Broken Authentication - Weak or missing authentication mechanisms 3. Broken Object Property Level Authorization - Missing field-level access control 4. Unrestricted Resource Consumption - No rate limiting or throttling 5. Broken Function Level Authorization - Missing authorization checks on endpoints 6. Unrestricted Access to Sensitive Business Flows - Automated abuse of legitimate workflows 7. Server Side Request Forgery (SSRF) - API accepts URLs without validation 8. Security Misconfiguration - Insecure default configs, verbose errors 9. Improper Inventory Management - Undocumented/deprecated APIs in production 10. Unsafe Consumption of APIs - Trusting third-party API data without validation

williamzujkowski/standards
11
0
更新於 1w ago

Unnamed Skill

Use before implementing UI changes or frontend PRs. Enforces TodoWrite with 18+ items. Triggers: "accessibility audit", "WCAG", "Lighthouse", "screen reader", "a11y", "NVDA", "VoiceOver", "keyboard navigation", "focus indicator". For "Core Web Vitals" in frontend/UI context, use this skill. For pure backend/API performance optimization, use performance-optimization instead. If thinking "WIP doesn't need this" - use it anyway.

pvillega/claude-templates
11
4
更新於 1w ago

testing-r-packages

Marketplace

Best practices for writing R package tests using testthat version 3+. Use when writing, organizing, or improving tests for R packages. Covers test structure, expectations, fixtures, snapshots, mocking, and modern testthat 3 patterns including self-sufficient tests, proper cleanup with withr, and snapshot testing.

posit-dev/skills
11
0
更新於 1w ago

code-review-helper

Systematic code review workflows with bundled utilities for analyzing code quality, detecting patterns, and providing structured feedback. Use this skill when reviewing pull requests or conducting code audits.

gptme/gptme-contrib
11
10
更新於 1w ago

nist-compliance

NIST 800-53r5 control implementation, tagging, evidence collection, and compliance automation for security frameworks

williamzujkowski/standards
11
0
更新於 1w ago

codex-code-review

Marketplace

Perform comprehensive code reviews using OpenAI Codex CLI. This skill should be used when users request code reviews, want to analyze diffs/PRs, need security audits, performance analysis, or want automated code quality feedback. Supports reviewing staged changes, specific files, entire directories, or git diffs.

tyrchen/claude-skills
11
1
更新於 1w ago