本文へ移動
cccskills

「implementation」の検索結果

3,105 件 ・ 関連度順

概要と使いどころ

JWT attack methodology for penetration testers. Covers algorithm confusion (alg:none, RS256→HS256), weak HMAC secret brute force, kid parameter injection (SQLi, path traversal), jku/x5u/jwk header injection, JWKS cache poisoning, JWS/JWE confusion, timing attacks, and mobile JWT storage extraction. Use when testing JWT-based authentication, hunting auth bypass via token manipulation, or evaluating JWT implementation security in web or mobile apps.

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Comprehensive methodology for auditing and exploiting TLS/SSL implementations and misconfigurations across network services and mobile applications. Covers protocol downgrade attacks including POODLE (CVE-2014-3566) against SSLv3 CBC padding, DROWN (CVE-2016-0800) cross-protocol attack leveraging SSLv2 export ciphers to decrypt TLS sessions, and FREAK (CVE-2015-0204) forcing RSA export-grade key exchange. Addresses BEAST (CVE-2011-3389) exploiting CBC IV predictability in TLS 1.0, CRIME (CVE-2012-4929) and BREACH targeting TLS-level and HTTP-level compression oracles respectively, and Heartbleed (CVE-2014-0160) for OpenSSL memory disclosure. Covers certificate validation bypass techniques for applications with improper hostname verification or chain validation, certificate pinning bypass using Frida and Objection for mobile application interception, HSTS bypass via NTP manipulation and subdomain exploitation, TLS 1.3 0-RTT replay attacks against non-idempotent endpoints, mutual TLS (mTLS) authentication a...

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Systematic methodology for identifying and exploiting cryptographic implementation weaknesses in real-world applications. Covers padding oracle attacks against CBC-mode ciphers with PKCS7 padding (Vaudenay's original attack through modern padbuster automation), ECB mode exploitation including block cut-and-paste and byte-at-a-time decryption, hash length extension attacks against SHA1/SHA256/MD5-based MACs using HashPump, RSA vulnerabilities including small public exponent, common modulus, Bleichenbacher PKCS1v1.5 padding oracle, and Coppersmith's method for partial key recovery. Addresses weak PRNG exploitation targeting time-seeded generators and Mersenne Twister MT19937 state recovery from observed outputs, timing side-channel attacks against comparison operations, nonce reuse in AES-GCM leading to authentication key recovery, and key derivation weaknesses including insufficient iteration counts and missing salts. Primary tooling includes padbuster, RsaCtfTool, hashpump, and PyCryptodome for building c...

日本語の概要は準備中です。原文の説明を表示しています。

ajtazer/heckit22026年10月7日 更新

Use when implementation is complete, all tests pass, and you need to decide how to integrate the work - guides completion of development work by presenting structured options for merge, PR, or cleanup

日本語の概要は準備中です。原文の説明を表示しています。

danstrem2/clawdbot-skill-master-pack22026年2月1日 更新

Use when you have a written implementation plan to execute in a separate session with review checkpoints

日本語の概要は準備中です。原文の説明を表示しています。

danstrem2/clawdbot-skill-master-pack22026年2月1日 更新

Orchestrates design workflows by routing work through brainstorming, multi-agent review, and execution readiness in the correct order. Prevents premature implementation, skipped validation, and unreviewed high-risk designs.

日本語の概要は準備中です。原文の説明を表示しています。

danstrem2/clawdbot-skill-master-pack22026年2月1日 更新

Expert patterns for Clerk auth implementation, middleware, organizations, webhooks, and user sync Use when: adding authentication, clerk auth, user authentication, sign in, sign up.

日本語の概要は準備中です。原文の説明を表示しています。

danstrem2/clawdbot-skill-master-pack22026年2月1日 更新

You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.

日本語の概要は準備中です。原文の説明を表示しています。

danstrem2/clawdbot-skill-master-pack22026年2月1日 更新

When the user wants to plan, design, or implement an A/B test or experiment. Also use when the user mentions "A/B test," "split test," "experiment," "test this change," "variant copy," "multivariate test," or "hypothesis." For tracking implementation, see analytics-tracking.

日本語の概要は準備中です。原文の説明を表示しています。

danstrem2/clawdbot-skill-master-pack22026年2月1日 更新

Expert patterns for Algolia search implementation, indexing strategies, React InstantSearch, and relevance tuning Use when: adding search to, algolia, instantsearch, search api, search functionality.

日本語の概要は準備中です。原文の説明を表示しています。

danstrem2/clawdbot-skill-master-pack22026年2月1日 更新

When the user wants to set up, improve, or audit analytics tracking and measurement. Also use when the user mentions "set up tracking," "GA4," "Google Analytics," "conversion tracking," "event tracking," "UTM parameters," "tag manager," "GTM," "analytics implementation," or "tracking plan." For A/B test measurement, see ab-test-setup.

日本語の概要は準備中です。原文の説明を表示しています。

danstrem2/clawdbot-skill-master-pack22026年2月1日 更新

Analyze any codebase's source code in depth and produce structured analysis documents saved as markdown files. Use this skill whenever the user asks to understand how a codebase works — architecture, module design, call flows, data models, design patterns, performance characteristics, or any implementation detail. Trigger on phrases like "analyze the source", "explain this code", "how does X work", "where is Y implemented", "trace the flow of", "what happens when", "read through the code", "code walkthrough", "源码分析", "代码解读", "实现原理", "架构分析", "调用链路", "模块分析", or any code-exploration request. Works with any programming language: TypeScript/JavaScript, Java, Python, Go, Rust, C/C++, and more. Even if the user's question seems simple (e.g., "这个文件是干什么的"), use this skill — a thorough, source-backed analysis document is always more valuable than a surface-level guess.

日本語の概要は準備中です。原文の説明を表示しています。

Scoheart/agentskills22026年8月4日 更新

Discovers and injects project-specific coding guidelines from .trellis/spec/ before implementation begins. Reads spec indexes, pre-development checklists, and shared thinking guides for the target package. Use when starting a new coding task, before writing any code, switching to a different package, or needing to refresh project conventions and standards.

日本語の概要は準備中です。原文の説明を表示しています。

ofoxai/skills22026年9月22日 更新

Guides collaborative requirements discovery before implementation. Creates task directory, seeds PRD, asks high-value questions one at a time, researches technical choices, and converges on MVP scope. Use when requirements are unclear, there are multiple valid approaches, or the user describes a new feature or complex task.

日本語の概要は準備中です。原文の説明を表示しています。

ofoxai/skills22026年9月22日 更新

Designs marketing automation workflows: email triggers, branching logic, lead scoring rules, lifecycle stage transitions. Outputs Mermaid diagrams and implementation specs for HubSpot, Klaviyo, and Mailchimp.

日本語の概要は準備中です。原文の説明を表示しています。

ekatasingh1107/b2b-gtm-skills22026年4月12日 更新

Expert in temporal event detection, spatio-temporal clustering (ST-DBSCAN), and photo context understanding. Use for detecting photo events, clustering by time/location, shareability prediction, place recognition, event significance scoring, and life event detection. Activate on 'event detection', 'temporal clustering', 'ST-DBSCAN', 'spatio-temporal', 'shareability prediction', 'place recognition', 'life events', 'photo events', 'temporal diversity'. NOT for individual photo aesthetic quality (use photo-composition-critic), color palette analysis (use color-theory-palette-harmony-expert), face recognition implementation (use photo-content-recognition-curation-expert), or basic EXIF timestamp extraction.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Designs, reconciles, and reviews an end-to-end Drydock program for safely staging agent runtimes: immutable worktree provenance, disposable VM containment, typed effect brokerage, global body accounting, resurrection, subscription-capacity economics, context compaction, operator control, evidence, and promotion. Use when several Drydock contracts must compose into one architecture, implementation hypertree, diagram set, or release plan. NOT for launching Port Daddy, running an untrusted subject, replacing focused containment/resurrection/capacity audits, or treating a design packet as runtime authority.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Aesthetic assessment and design scoring across 6 dimensions. Use for UI critique, design review, visual quality assessment, remix suggestions. Activate on "design critique", "aesthetic review", "UI assessment", "visual quality", "design score", "remix this design". NOT for implementation (use frontend-developer), accessibility-only audits (use color-contrast-auditor), or brand identity creation.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Star schema, snowflake schema, SCD types, and Kimball methodology for analytical data modeling. Activate on: dimensional model, star schema, snowflake schema, SCD, fact table, dimension table, Kimball, grain, surrogate key. NOT for: dbt implementation (use dbt-analytics-engineer), warehouse tuning (use data-warehouse-optimizer).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Builds comprehensive design systems and design bibles with production-ready CSS. Expert in design tokens, component libraries, CSS architecture. Use for design system creation, token architecture, component documentation, style guide generation. Activate on "design system", "design tokens", "CSS architecture", "component library", "style guide", "design bible". NOT for typography deep-dives (use typography-expert), color theory mathematics (use color-theory-palette-harmony-expert), brand identity strategy (use web-design-expert), or actual UI implementation (use web-design-expert or native-app-designer).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Specifies bounded DAG execution contracts and evaluates executor receipts for dispatch, cancellation, joins, and effect reconciliation. Use when an implementation must bind a planned DAG to named runtime controls. NOT for claiming an executor is active, spawning agents, or certifying an effect from a plan.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Diagnose when intuitive judgment, agent confidence, or expert routing can be trusted by classifying environment validity, feedback quality, and task-boundary fit. Use for confidence calibration, agent routing, expertise audits, and escalation design. NOT for deterministic implementation tasks, pure syntax debugging, or domains with explicit verifiable answers.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Diagnose when intuitive judgment, agent confidence, or expert routing can be trusted by classifying environment validity, feedback quality, and task-boundary fit. Use for confidence calibration, agent routing, expertise audits, and escalation design. NOT for deterministic implementation tasks, pure syntax debugging, or domains with explicit verifiable answers.

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新

Own whether a multi-document product-architecture binder is internally consistent, complete against its stated customer/contingency/architecture coverage, and honest about which older product ambitions it has absorbed, superseded, deferred, contradicted, orphaned, or rejected. Use when running a binder Architect of Record pass, before an implementation chain cites a binder chapter as ready, when a proof-gate owner is missing, or when reconciling the binder against the older ambition corpus (website, plans, examples, ADRs). NOT for auditing a single Claude Skill bundle's structure or frontmatter (use skill-hygiene), rendering a single-PM accept/reject verdict on one finished deliverable (use port-daddy-user-surrogate-pm-review), or sequencing/stewarding a roadmap's sidequests once a gap or operator decision has been surfaced (use legible-roadmap-with-sidequests).

日本語の概要は準備中です。原文の説明を表示しています。

curiositech/port-daddy22026年10月8日 更新