Multi-path document generation with tool checks, Unicode handling, and Python fallbacks
日本語の概要は準備中です。原文の説明を表示しています。
61 件 ・ 関連度順
概要と使いどころ
Multi-path document generation with tool checks, Unicode handling, and Python fallbacks
日本語の概要は準備中です。原文の説明を表示しています。
LLM application red-teaming — prompt injection (direct + indirect), jailbreak, system-prompt leak, data exfiltration, guardrail bypass, multi-turn crescendo, cross-lingual + cipher + invisible-unicode token smuggling, excessive agency / tool abuse, insecure output handling. Canonical OWASP LLM Top 10 + ASI01-ASI10 mapping. Use when a target exposes a chat/completions/assistant/copilot endpoint, an AI feature that consumes user text or documents, or any /v1/chat, /api/chat, /mcp surface.
日本語の概要は準備中です。原文の説明を表示しています。
Draft or reformat copy-paste-ready LinkedIn posts from user-provided ideas and source material. Use for professional posts, concise thought-leadership drafts, resource announcements, story-led posts, carousel text, or optional Unicode emphasis with an accessible plain-text alternative.
日本語の概要は準備中です。原文の説明を表示しています。
Hunt LLM/AI feature bugs — prompt injection, indirect injection, exfiltration via tool-use/markdown, ASCII smuggling, agentic AI security (OWASP Agentic Apps 2026, ASI01-ASI10). Patterns: direct injection ('ignore previous instructions'), indirect injection via documents/web pages/email the model reads, ASCII smuggling (Unicode Tags block U+E0000-U+E007F, invisible to humans, decoded by the model), tool-use exfiltration (model has fetch/browse tool, attacker injects OOB URL, model exfils chat history/secrets), markdown-image zero-click exfil, system-prompt extraction, IDOR-via-AI (cross-tenant data). Targets: chatbots, RAG, summarizers, agentic copilots, MCP tools. Detection: any LLM-backed endpoint, doc upload triggering AI processing, autonomous agent with tools. Validate: OOB/Collaborator callback for exfil, verbatim-reproducible system-prompt leak (run twice), verifiable cross-tenant leak or RCE. Confabulation is NOT a finding. Use when hunting AI features, chatbots, RAG, agentic systems, MCP.
日本語の概要は準備中です。原文の説明を表示しています。
编码解码与加解密工具 — base64/URL/Hex/HTML实体编码解码,MD5/SHA哈希,AES/DES/RSA加解密,JWT解析,Caesar/ROT13密码,栅栏/Vigenere密码,Unicode转义,Morse电码等
日本語の概要は準備中です。原文の説明を表示しています。
Provides miscellaneous CTF challenge techniques for problems that do not cleanly fit the main categories. Use for encoding puzzles, pyjails, bash jails, RF/SDR, DNS oddities, unicode tricks, esoteric languages, QR or audio puzzles, constraint solving, game theory, unusual sandbox escapes, and hybrid logic puzzles. Prefer a more specific skill first when the challenge is mainly web, pwn, reverse, forensics, malware, OSINT, or crypto. Treat this as the fallback skill for genuine cross-category or edge-case challenges, not the default starting point.
日本語の概要は準備中です。原文の説明を表示しています。
Terminal security analysis for shell environments. This skill should be used when checking commands for supply-chain attacks before execution, scanning repositories for hidden content or config poisoning, scoring URLs for homograph attacks, setting up AI tool protection, inspecting Python package artifacts, governing untrusted tasks or Web3 commands, auditing browser extensions, creating provenance receipts, downloading and executing scripts safely, investigating why tirith blocked a command, managing trusted patterns, running security audits, configuring MCP gateway proxies, or working with threat intelligence databases. Also use when the user mentions "tirith", "pipe-to-shell", "homograph", "ANSI injection", "zero-width", "punycode", "terminal security", "shell hook", "cloaking detection", "supply chain attack", "bidi override", "invisible unicode", or "config poisoning". Even if the user does not explicitly name tirith, use this skill when they ask about protecting shell environments, intercepting dangerous commands, or hardening AI agent tool execution.
日本語の概要は準備中です。原文の説明を表示しています。
Contain an encoded Unicode Tag Block marker used for hidden instructions
日本語の概要は準備中です。原文の説明を表示しています。
Generate and render Mermaid diagrams for architecture docs, READMEs, PRs, terminals, chats, and CI as themed SVG, PNG, or ASCII/Unicode art. Use this skill whenever the user provides Mermaid code or .mmd files; asks for a flowchart, sequence/state/class diagram, ERD, XY chart, or architecture/workflow/data-model visualization; or wants to beautify, theme, batch-convert, or make a diagram terminal-friendly. Runs locally without a browser or DOM, with 15 built-in themes and custom colors.
日本語の概要は準備中です。原文の説明を表示しています。
Detects prompt injection hidden in documents from the other side (pleadings, skeletons, bundles, served evidence, opponents' emails and attachments) before an AI reads them, so the model is not turned against your client. Checks word by word that the text an extractor hands the model was visibly drawn on the page: white, near-white, covered, clipped, off-page, tiny, transparent and invisible-mode text in PDF (ink test plus OCR); Word formatting resolved as Word does (styles, shading, theme colours, scaling, off-page frames, fallbacks, unused headers); HTML/CSS, RTF, email with attachments and zips, xlsx/pptx and legacy formats. Flags Unicode smuggling, text addressed to an AI and authorities found only in hidden text. Fails closed. Optional Read-tool hook. Use BEFORE any AI summary or analysis of an opposing or third-party document. Triggers: 'scan for injection', 'is this document safe', 'check the other side's skeleton', 'injection guard'.
日本語の概要は準備中です。原文の説明を表示しています。
用于编码题、pyjail、bash jail、RF/SDR、DNS 异常、Unicode、奇特语言、QR、音频、约束求解、博弈论与沙箱逃逸等跨类或边缘 CTF 题;触发名:ctf-misc
日本語の概要は準備中です。原文の説明を表示しています。
科学公式/化学式规整 Skill:统一文本列中的数学符号、Unicode 上下标、化学反应箭头、全角 ASCII 和多余空格。 适用于实验记录、论文摘录、化学反应式和科学公式文本;不负责公式语义解析、单位换算或化学配平。
日本語の概要は準備中です。原文の説明を表示しています。
PDF/OCR伪影清洗工具。修复从学术论文PDF提取文本时的常见问题:断行连字符拼接(dehyphenation)、 页码去除、Unicode连字归一化(fi→fi)、页眉页脚去除。 当用户提到PDF文本清洗、OCR伪影处理、断行修复、连字符拼接等需求时使用此skill。
日本語の概要は準備中です。原文の説明を表示しています。
全角/半角字符规范化工具。读取结构化数据文件,将文本中的全角ASCII字符(字母、数字、标点)转换为半角形式, 并可按需执行指定 Unicode 正规化。适用于中日韩混排科研文本的统一预处理,不负责空白行删除、拼写纠错或重复标点合并。 当用户提到全角转半角、半角规范化、全半角统一、全角字母数字转换等需求时使用此skill。
日本語の概要は準備中です。原文の説明を表示しています。
括号类型统一工具。读取结构化数据文件,执行中文/全角括号到 ASCII 半角括号的映射,输出括号已统一的结构化数据文件。 当用户提到括号统一、全角括号转半角、中文括号转换、括号规范化等需求时使用此skill。 即使用户没有明确说出"bracket_normalizer",只要任务涉及括号类符号统一,就应该使用此skill。 不负责全角字母数字转换、Unicode正规化或其他通用全半角处理。
日本語の概要は準備中です。原文の説明を表示しています。
Workaround for Claude Code filtering BMP PUA Unicode (U+E000-U+F8FF). Supplementary PUA Nerd Font icons like (U+F0000+, e.g. nf-md-github, nf-md-kubernetes, nf-md-battery) can be written directly. BMP PUA icons (Powerline, Font Awesome, Devicons) require placeholder syntax like {{ U+E0A0 }} or {{ nf-fa-star }} (without spaces), which hooks auto-convert. Invoke when reading or writing Starship configs, tmux themes, shell prompts, or statuslines.
日本語の概要は準備中です。原文の説明を表示しています。
Create Chinese monospaced compass-style PDCA or CAPD problem-solving cards using East-West-South-North-Center layout, full-width and half-width spaces, diagonal Unicode arrows, and strict Chinese character limits. Use when Codex needs to turn a problem, incident, decision tradeoff, root-cause analysis, improvement cycle, or CAPD/PDCA workflow into a square text diagram, Hermes/Discord-ready card, or Chinese 方位九宮圖 with center ◎, north Plan, east Do, south Check, west Action, and four diagonal transition arrows.
日本語の概要は準備中です。原文の説明を表示しています。
Heuristic security scan of installed skills — prompt-injection phrases, hidden unicode instructions, credential-store access, network-pipe-to-shell and payload-smuggling patterns. Use when the user asks 'are my skills safe', wants to scan skills for prompt injection or malware patterns, or before trusting a newly installed skill. Trigger with '/janitor-security'.
日本語の概要は準備中です。原文の説明を表示しています。
Use when writing Python scripts that must run on Windows, Linux, and macOS — especially when Rich or Typer output breaks on Windows, when dealing with Unicode/encoding errors, ANSI escape handling, terminal detection, path separators, or console color support. Provides verified cross-platform patterns covering stdout/stderr encoding guards, Windows console quirks, terminal capability detection, and portable I/O for CLI, TUI (Rich/Textual), and GUI environments.
日本語の概要は準備中です。原文の説明を表示しています。
Render Mermaid diagrams as ASCII/Unicode art for terminal display or as SVG files. Use when visualizing flowcharts, state machines, sequence diagrams, class diagrams, or ER diagrams. Supports 17 themes (including vellum, tokyo-night, catppuccin, nord, dracula, github) plus custom colors via --colors JSON.
日本語の概要は準備中です。原文の説明を表示しています。
Exploit path traversal and local/remote file inclusion (LFI/RFI) via URL parameters, cookies, and hidden fields using ../ sequences, URL encoding (%2e%2e%2f), double encoding (%252e%252e%255c), Unicode bypasses (..%c0%af), and Windows UNC paths. PHP include/require with $_GET/$_POST/$_COOKIE pattern. Target /etc/passwd, boot.ini, web.config. Tools: DotDotPwn, WFuzz, Burp Suite, ZAP.
日本語の概要は準備中です。原文の説明を表示しています。
Extracts ASCII and Unicode strings from a binary and classifies them into investigative categories: URLs, IPs, file paths, registry keys, mutexes, commands, and API names, prioritizing the analyst's attention. Activates for requests to extract strings, classify strings output, or pull human-readable artifacts from a sample.
日本語の概要は準備中です。原文の説明を表示しています。
Evaluate page content for usefulness, E-E-A-T, readability, thinness, and AI citation readiness, plus last-mile draft cleanup (AI-typical phrasing and invisible Unicode watermark characters). Use for content-only analysis, not full-page technical checks.
日本語の概要は準備中です。原文の説明を表示しています。
Handle Chinese mojibake in CMD, .bat/.cmd files, Windows logs, and native command output by using PowerShell to read raw bytes as GBK/CP936, capture command output with an explicit decoder, and convert it to UTF-8/Unicode. Use when text contains 锟斤拷, mojibake, or replacement characters and the source encoding must be verified.
日本語の概要は準備中です。原文の説明を表示しています。