本文へ移動
cccskills

「mapping」の検索結果

1,171 件 ・ 関連度順

概要と使いどころ

Apply a set of Rosetta Stone attribute mappings to a Narrative dataset by wrapping them in a one-shot workflow that calls the `CreateRosettaStoneMappingsIfNotExist` task. Consumes the structured output of `/generate-rosetta-stone-mappings`, normalizes the generator's snake_case to the workflow task's camelCase, re-validates every expression against the dataset's current schema, gates on user approval, submits via `narrative_workflows_create`, polls the triggered run, and reports per-mapping created / conflict / failed. Use when: "apply these mappings to dataset N", "create the Rosetta Stone mappings I just generated", "push the mappings I saved earlier to <dataset>", "productionize this mapping list", "submit the suggested_mappings array". (narrative-common)

日本語の概要は準備中です。原文の説明を表示しています。

narrative-io/narrative-skills-marketplace92026年10月10日 更新

Map Delphi classes to a relational database using TMS Aurelius ORM attributes. Use when the user asks to create entity classes, add Aurelius mapping to existing classes, fix or review mapping attributes, explain how a class is mapped, or work with associations, inheritance, automapping, nullable fields, blobs, or composite identifiers. Triggers on requests like "create Aurelius entities for...", "map this class to Aurelius", "add ORM mapping", "fix the mapping on this class", "how do I map a one-to-many in Aurelius".

日本語の概要は準備中です。原文の説明を表示しています。

tmssoftware/skills142026年4月16日 更新

Generate, evaluate, and improve Rosetta Stone attribute mappings for a Narrative dataset. Use when: "map this dataset to Rosetta Stone", "suggest normalized attributes for dataset N", "evaluate the mappings on dataset N", "why is this mapping low confidence", "fix this expression", "improve this NQL mapping expression". (narrative-common)

日本語の概要は準備中です。原文の説明を表示しています。

narrative-io/narrative-skills-marketplace92026年10月10日 更新

Provides patterns for unit testing mappers, converters, and bean mappings. Validates entity-to-DTO and model transformation logic in isolation. Generates executable mapping tests with MapStruct and custom converter test coverage. Use when writing mapping tests, converter tests, entity mapping tests, or ensuring correct data transformation between DTOs and domain objects.

日本語の概要は準備中です。原文の説明を表示しています。

giuseppe-trisciuoglio/developer-kit3572026年9月10日 更新

Guides systematic mapping of international personal data flows across an organisation. Covers system-by-system inventory methodology, third-party identification, transfer mechanism assignment, gap analysis, and data flow visualisation. Keywords: data flow mapping, international transfers, data inventory, transfer register, cross-border data flows.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Privacy-Data-Protection-Skills3022026年3月17日 更新

Harmonises data classification across jurisdictions mapping GDPR special categories vs CCPA sensitive PI (1798.140(ae)) vs HIPAA PHI (160.103) vs LGPD sensitive data (Art. 5-II). Provides cross-regulation mapping matrix for multinational compliance. Keywords: cross-jurisdiction, GDPR, CCPA, HIPAA, LGPD, sensitive data, multinational, classification mapping.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Privacy-Data-Protection-Skills3022026年3月17日 更新

Expert knowledge for real-time and baked lighting in games - from cinematography fundamentals to engine-specific optimization, covering GI, time-of-day, volumetrics, and platform-aware lighting pipelinesUse when "lighting, light design, baked lighting, realtime lighting, lightmap, lightmapping, light probe, reflection probe, global illumination, GI, ambient occlusion, shadow, shadow cascade, time of day, day night cycle, volumetric fog, volumetric lighting, god rays, HDR, tonemapping, bloom, exposure, emissive, area light, Lumen, Enlighten, ray tracing, RTGI, light baking, lighting, global-illumination, lightmapping, shadows, GI, light-probes, reflection-probes, HDR, tonemapping, volumetric, fog, time-of-day, baked, realtime, mixed-lighting, lumen, enlighten, radiosity, ray-tracing, RTGI" mentioned.

日本語の概要は準備中です。原文の説明を表示しています。

omer-metin/skills-for-antigravity1642026年1月22日 更新

Configuring Salesforce lead management and conversion in Setup: lead settings, web-to-lead, conversion field mapping, lead queues, auto-response rules, lead processes. Trigger keywords: web-to-lead, lead conversion, lead field mapping, lead settings, lead process, lead queue, lead auto-response. NOT for Apex that controls what conversion creates - use apex/lead-conversion-customization. NOT for lead assignment rule logic - use admin/assignment-rules. NOT for duplicate rule configuration - use admin/duplicate-management. Also covers: LeadConvertSettings objectMapping XML, LeadConfigSettings, LeadStatus StandardValueSet converted flag, lead process BusinessProcess, Database.convertLead bulk conversion limits.

日本語の概要は準備中です。原文の説明を表示しています。

PranavNagrecha/AwesomeSalesforceSkills192026年10月4日 更新

mybatis-patterns

無料日本語概要

MyBatisを使うJavaのデータ保存・取得処理を設計、レビューします。SQLと結果の対応付け、動的SQLの安全性、トランザクションや検索性能を扱います。

  • マッパーとXMLの対応付けの設計
  • 動的SQLと入力値の安全性確認
  • 複数更新のトランザクション確認
affaan-m/ECC27.7万2026年10月10日 更新

Connects Figma design components to code components using Code Connect mapping tools. Use when user says "code connect", "connect this component to code", "map this component", "link component to code", "create code connect mapping", or wants to establish mappings between Figma designs and code implementations. For canvas writes via `use_figma`, use `figma-use`.

日本語の概要は準備中です。原文の説明を表示しています。

openai/skills2.8万2026年9月9日 更新

Organization-grade identity-fabric mapping: tenant/federation fingerprinting and the pre-auth user-ENUMERATION oracle methodology — enumeration and fingerprint only, never credential submission. Covers domain-to-tenant resolution (Microsoft getuserrealm.srf Managed/Federated namespace check, Entra OIDC metadata tenant-GUID extraction, Autodiscover v2), keyless Microsoft tenant-federation mapping (GetFederationInformation SOAP -> sibling-domain discovery, discover-only ROE, FEDERATED_WITH provenance edge held out of attack-path pivoting), Okta org-slug derivation + OIDC fingerprint + governed custom-domain enumeration, ADFS passive/active fingerprint + version inference, Google Workspace MX-correlated detection, generic OIDC (Auth0/Keycloak/Ping Identity/OneLogin/Duo) discovery, SAML metadata (5 paths), Azure AD Seamless-SSO Negotiate-challenge detection, Microsoft Defender for Identity (MDI) sensor-API presence check, the user-enumeration oracle methodology for Microsoft GetCredentialType (IfExistsResult semantics: exists / doesn't-exist / exists-in-federated-tenant / throttled) and Okta /api/v1/authn (errorCode differential), Medium-detectability discipline with a hard 20-candidate-per-tenant cap and admin/role interest-based ranking, and name x confirmed-email-pattern login-candidate synthesis that FAILS CLOSED with zero output when no org pattern is confirmed. Grounded directly in a production ASM implementation's sso_idp.py, tenant_recon.py, and core/email_patterns.py modules. Deepens — does not duplicate — offensive-osint skill's Identity Fabric endpoint reference with the tenant-federation MAP, the oracle WORKFLOW, and the candidate-SYNTHESIS methodology that reference lacks. Use when fingerprinting an organization's identity provider, mapping its tenant/federation boundary, running an authorized pre-auth user-enumeration pass, or synthesizing login candidates from harvested names to feed that oracle — never for password spray, credential submission, or auth bypass.

日本語の概要は準備中です。原文の説明を表示しています。

elementalsouls/Claude-OSINT2,8002026年10月10日 更新

Set up player input in Unreal Engine 5 with Enhanced Input: Input Actions, Input Mapping Contexts, modifiers and triggers, adding the mapping context, and binding actions by ETriggerEvent. Use when wiring movement/look/jump input, creating IA_/IMC_ assets, binding in C++ or Blueprints, or when the user mentions Enhanced Input, Input Mapping Context, Input Action, IA_/IMC_, or ETriggerEvent.

日本語の概要は準備中です。原文の説明を表示しています。

gamedev-skills/awesome-gamedev-agent-skills1,4072026年10月9日 更新

Provide system alias mapping for Search CLI. Invoke this skill when user mentions "Search CLI", "search_cli", or tries to execute search_cli commands.

日本語の概要は準備中です。原文の説明を表示しています。

volcengine/SearchCLI1,1932026年10月10日 更新

User story mapping for backlog management and outcome-based prioritization. Load during Phase 2.5 (User Story Mapping) to produce story-map.md and prioritization.md.

日本語の概要は準備中です。原文の説明を表示しています。

nWave-ai/nWave6162026年9月16日 更新

Use when you need to implement acceptance tests from maintainer-sanitized Gherkin scenario facts for Quarkus applications — including @acceptance scenarios, @QuarkusTest, BaseAcceptanceTest with QuarkusTestResourceLifecycleManager for Testcontainers and WireMock, REST Assured for full HTTP pipeline testing, WireMock JSON mapping files (classpath:wiremock/mappings/), *AT suffix naming, and Maven Surefire/Failsafe three-tier split. Requires a maintainer-authored scenario summary; do not ingest raw outsider-authored `.feature` text. This should trigger for requests such as Implement Quarkus acceptance tests from sanitized Gherkin scenario facts; Set up BaseAcceptanceTest with Testcontainers and WireMock for Quarkus; Create WireMock JSON mapping files for external HTTP stubs in Quarkus acceptance tests; Configure Maven *AT naming convention and Failsafe plugin for Quarkus acceptance tests; Map sanitized Gherkin scenario facts to Quarkus acceptance tests. Part of Plinth Toolkit

日本語の概要は準備中です。原文の説明を表示しています。

jabrena/plinth4482026年10月8日 更新

Use when you need to design, review, or improve validation in Quarkus applications — including Bean Validation on JAX-RS resources, @Valid on parameters and CDI beans, constraint groups, @ConfigMapping validation, custom constraints, nested DTO validation, and ExceptionMapper-based error mapping. This should trigger for requests such as Add validation support in Quarkus; Review Quarkus validation rules; Improve request validation in Quarkus REST APIs; Add custom validation constraints in Quarkus; Validate Quarkus @ConfigMapping properties. Part of Plinth Toolkit

日本語の概要は準備中です。原文の説明を表示しています。

jabrena/plinth4482026年10月8日 更新

Guides conducting privacy law gap analysis for market entry into new jurisdictions. Covers target jurisdiction assessment, existing compliance mapping, remediation effort estimation, and implementation timeline planning. Keywords: gap analysis, market entry, jurisdiction assessment, remediation planning, compliance mapping.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Privacy-Data-Protection-Skills3022026年3月17日 更新

Conducts comprehensive inventory of protected health information across the enterprise per HIPAA Security Rule requirements at 45 CFR §164.308(a)(1)(ii)(A) and §164.310(d). Covers identification of all ePHI repositories, data flow mapping, classification of PHI by sensitivity, and integration with risk analysis. Keywords: PHI inventory, ePHI, data mapping, information asset, data flow, HIPAA risk analysis, designated record set.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Privacy-Data-Protection-Skills3022026年3月17日 更新

Implements data lineage tracking for privacy compliance including origin tracking, transformation logging, access auditing, deletion verification, and cross-system lineage graphs. Covers source-to-sink mapping, GDPR Art. 30 RoPA integration, automated lineage discovery, and breach impact scoping. Keywords: data lineage, data provenance, data flow mapping, transformation logging, deletion verification.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Privacy-Data-Protection-Skills3022026年3月17日 更新

Builds comprehensive data inventory per GDPR Art. 30 Records of Processing Activities. Covers system-by-system discovery, data flow diagramming, third-party identification, and legal basis per category. Keywords: data inventory, data mapping, Art 30, RoPA, data flow, processing activities.

日本語の概要は準備中です。原文の説明を表示しています。

mukul975/Privacy-Data-Protection-Skills3022026年3月17日 更新

A high-level conceptual mapping from Active Directory attack techniques to the compliance controls they touch. Kerberoasting relates to authentication and logging, so it brushes ENS op.acc.5 / op.exp.8, NIS2 Art.21(2)(h), DORA RTS Art.9 / Art.21. Use this when a reader wants to understand which regulatory control an AD finding relates to, or to add an orientation note to a technical finding. This is a conceptual, orientative mapping only; it is NOT an auditor-defensible, curated, ID-by-ID control matrix. Covers ENS (op.acc.*, op.exp.*), NIS2 (Directive 2022/2555 Art.21), and DORA (RTS 2024/1774).

日本語の概要は準備中です。原文の説明を表示しています。

ADScanPro/Claude-AD2112026年8月25日 更新

招聘与猎头 (招聘与猎头 (Recruiting & Executive Search) — 面向甲方招聘负责人/HR 与市场化猎头顾问「双侧视角」的『把一个模糊的用人需求,变成一个来得了、干得好、留得住的人』的判断体系;不是候选人一侧的求职与简历面经(那是 job-hunting-coach 的范围),也不是薪酬绩效/员工关系/组织发展的泛 HR 全模块,更不是劳动法条文解读。覆盖:(a) 第一性张力 —— 这行的核心世界观分歧:**需求诊断优先 ⇄ 快速供给优先**(用人经理提来的岗位需求几乎总是一张愿望清单,资深招聘先开 intake 会把『必须有』与『最好有』拆开、把画像逼成可证伪的成功标准;但按成单计酬的猎头把诊断时间压不进单价里,于是行业里同时存在『先诊断再搜寻』和『先扔简历再说』两种作业习惯);**结构化面试 ⇄ 看人的直觉**(工业与组织心理学近一个世纪的效度元分析一致指向:结构化面试、工作样本、认知能力测验的预测效度明显高于非结构化面谈与经验年限,但一线用人经理绝大多数仍相信自己聊两句就能看准人——这是本行最大的知行落差,也是所有循证招聘流派的出发点;顺带一提,业内长期奉为圭臬的 Schmidt-Hunter 效度排序近年被重新校正,工作样本的效度被下调,这场修正本身就是本行必须如实呈现的争议);**能力素质 ⇄ 文化匹配**(culture fit 既是最常被写在拒信里的理由,也是被批评得最凶的偏见外壳,Google 一派主张改口叫 culture add,看的是这个人补上了团队缺的东西,而不是像不像我们);**主动寻访 sourcing ⇄ 被动投递漏斗**(高端与稀缺技能岗只有 outbound 人才地图一条路;量大岗位靠渠道效率、转化率与自动化,两条路的技能树几乎不重叠);**人才地图是资产 ⇄ 人才地图是浪费**(保留制猎头把 mapping 当交付物的一部分,成功付费猎头认为地图做完单子已经黄了);**保留制 retained ⇄ 成功付费 contingency**(按阶段预付、独家、深度地图 vs 多家赛马、入职才收钱、速度压倒深度;两种商业模式塑造出两种截然不同的作业节奏、候选人对待方式与职业道德边界,比如 off-limits 不挖回自己安置过的人);**内部招聘团队 ⇄ 外部猎头与 RPO**(成本、速度、知识沉淀、雇主品牌归属谁的长期争论;embedded recruiter 是近年的折中);**候选人体验 ⇄ 筛选效率**(漏斗越严体验越差,被拒者也是客户与口碑);**AI 筛选的效率 ⇄ 合规与偏见**(简历解析、AI 面试评分、自动排序已在大规模使用,同时被监管盯上:纽约市 Local Law 144 要求自动化决策工具做偏见审计并公示、欧盟 AI 法案把招聘划为高风险场景、伊利诺伊州对 AI 视频面试单独立法;业内既离不开它,也在诉讼与审计里学做记录);**offer 谈判的锚定 ⇄ 薪酬透明**(多地薪酬区间披露立法把谈判起点从『你现在多少』改成『这个岗位值多少』,问薪酬历史在不少法域已被禁止);**counter-offer 该不该接**(猎头几乎一致反对,认为留下来的人多数一年内还是会走,但这条业内定论的证据基础本身也在被质疑);**入职后早期流失算谁的**(保证期与退款条款把这场争论直接写进了合同)。(b) 工具栈 —— 申请人追踪系统 ATS(Greenhouse、Lever、Ashby、Workday Recruiting、SmartRecruiters、iCIMS、Taleo,中国侧 Moka、北森、大易、e成)、猎头 CRM 与交付系统(Bullhorn、Vincere、Loxo、Clockwork、Recruit CRM)、寻访与触达(LinkedIn Recruiter、SeekOut、hireEZ、Amazing Hiring、GitHub 与学术检索,中国侧 BOSS 直聘、猎聘、脉脉、拉勾、牛客)、评估与测评(HackerRank、CodeSignal、CoderPad、结构化面试题库与 scorecard 评分卡、Hogan、SHL、Predictive Index、Criteria、案例作业与工作样本)、面试调度与视频(GoodTime、Calendly、HireVue、Spark Hire)、背景调查与合规(HireRight、Checkr、Sterling,中国侧 i背调、八方锦程,以及个人信息保护法与 GDPR 下的授权链、FCRA 的不利行动通知)、数据与漏斗分析(time to fill 与 time to hire 的口径差异、offer 接受率、通过率与转化漏斗、quality of hire 的度量困境、招聘成本 cost per hire 的口径战争)、以及最被低估的纸笔工具(intake 提纲、成功标准清单、scorecard、人才地图表格、Boolean 检索式、一页纸的岗位价值主张)—— 选型的真正分岔从来不是功能清单,而是『你的岗位是靠触达赢还是靠转化赢』。(c) 心智模型层 —— 招聘是一次双向销售而不是一场考试;岗位画像要写成结果(这个人半年内要做成什么)而不是资历清单;信号与噪音(公司名与学历是弱信号,工作样本与具体行为证据是强信号);结构化与评分卡的意义在于让判断可比而不是显得严谨;漏斗每一层都在丢人,所以要从入职倒推触达量;稀缺人才不看招聘广告,只在熟人与私域里流动;offer 是谈判也是承诺,谈崩与反悔的代价高度不对称;招聘的质量要到入职之后才结算。(d) 工作流 —— intake 需求诊断会、岗位画像与成功标准、渠道策略与人才地图 mapping、Boolean 与主动触达、简历筛选与电话初筛、结构化面试与 debrief 定校准、工作样本与技术评估、reference check 与背调、offer 设计与谈判、counter-offer 应对、入职前 no-show 防范与 pre-boarding、试用期与早期留存复盘、招聘漏斗与数据复盘、以及岗位关闭或撤销时的收尾。(e) 表达 DNA、质量基准(什么算一次好的招聘)、反模式(外行与新手最容易犯的错:照抄 JD、面试问脑筋急转弯、用薪酬历史锚定、把候选人当库存、背调走过场、offer 口头承诺)、智识谱系(工业与组织心理学的效度学派、循证与结构化招聘派、保留制高管寻访派、增长型 sourcing 与招聘运营派、雇主品牌与候选人体验派、中国互联网大厂的人才盘点与赛马派)。) Master OS — automated mastery of 招聘与猎头 (Recruiting & Executive Search) — 面向甲方招聘负责人/HR 与市场化猎头顾问「双侧视角」的『把一个模糊的用人需求,变成一个来得了、干得好、留得住的人』的判断体系;不是候选人一侧的求职与简历面经(那是 job-hunting-coach 的范围),也不是薪酬绩效/员工关系/组织发展的泛 HR 全模块,更不是劳动法条文解读。覆盖:(a) 第一性张力 —— 这行的核心世界观分歧:**需求诊断优先 ⇄ 快速供给优先**(用人经理提来的岗位需求几乎总是一张愿望清单,资深招聘先开 intake 会把『必须有』与『最好有』拆开、把画像逼成可证伪的成功标准;但按成单计酬的猎头把诊断时间压不进单价里,于是行业里同时存在『先诊断再搜寻』和『先扔简历再说』两种作业习惯);**结构化面试 ⇄ 看人的直觉**(工业与组织心理学近一个世纪的效度元分析一致指向:结构化面试、工作样本、认知能力测验的预测效度明显高于非结构化面谈与经验年限,但一线用人经理绝大多数仍相信自己聊两句就能看准人——这是本行最大的知行落差,也是所有循证招聘流派的出发点;顺带一提,业内长期奉为圭臬的 Schmidt-Hunter 效度排序近年被重新校正,工作样本的效度被下调,这场修正本身就是本行必须如实呈现的争议);**能力素质 ⇄ 文化匹配**(culture fit 既是最常被写在拒信里的理由,也是被批评得最凶的偏见外壳,Google 一派主张改口叫 culture add,看的是这个人补上了团队缺的东西,而不是像不像我们);**主动寻访 sourcing ⇄ 被动投递漏斗**(高端与稀缺技能岗只有 outbound 人才地图一条路;量大岗位靠渠道效率、转化率与自动化,两条路的技能树几乎不重叠);**人才地图是资产 ⇄ 人才地图是浪费**(保留制猎头把 mapping 当交付物的一部分,成功付费猎头认为地图做完单子已经黄了);**保留制 retained ⇄ 成功付费 contingency**(按阶段预付、独家、深度地图 vs 多家赛马、入职才收钱、速度压倒深度;两种商业模式塑造出两种截然不同的作业节奏、候选人对待方式与职业道德边界,比如 off-limits 不挖回自己安置过的人);**内部招聘团队 ⇄ 外部猎头与 RPO**(成本、速度、知识沉淀、雇主品牌归属谁的长期争论;embedded recruiter 是近年的折中);**候选人体验 ⇄ 筛选效率**(漏斗越严体验越差,被拒者也是客户与口碑);**AI 筛选的效率 ⇄ 合规与偏见**(简历解析、AI 面试评分、自动排序已在大规模使用,同时被监管盯上:纽约市 Local Law 144 要求自动化决策工具做偏见审计并公示、欧盟 AI 法案把招聘划为高风险场景、伊利诺伊州对 AI 视频面试单独立法;业内既离不开它,也在诉讼与审计里学做记录);**offer 谈判的锚定 ⇄ 薪酬透明**(多地

日本語の概要は準備中です。原文の説明を表示しています。

swaylq/master-skill1492026年9月6日 更新

红队渗透 / 攻防 — 受授权的红队作业者 + 渗透测试工程师 + 攻击型安全顾问的认知操作系统 (侦察 OSINT / 外网渗透 / 内网 AD 渗透 BloodHound + Kerberoasting + ADCS 利用 + 横向移动 / Web 应用渗透 OWASP WSTG / 移动 OWASP MASTG / 云渗透 AWS Azure GCP IAM 路径 + 容器逃逸 + K8s / C2 操作 Cobalt Strike Sliver Mythic Havoc + OPSEC / 初始访问 + AV EDR 绕过 (仅授权场景) / 无线 RF / 物理社工 / 报告与整改 / 框架 MITRE ATT&CK + D3FEND + PTES + OSSTMM + NIST 800-115 + Kill Chain / 法律伦理 CFAA + 网络安全法 + 刑法 285 286 + 数据安全法 + GDPR + 授权书 + 范围 + 交战规则 — 不含 黑产 / 未授权攻击 / 大规模 exploitation / 供应链投毒 / 未授权 DoS — 这是 重罪 + 行业封杀 + 律师吊销, 本 skill 严守 authorized-only 边界 — 也不含 蓝队 SOC + 恶意软件 即服务 / 僵尸网络 / 勒索软件作者 — 这是 cybercrime 不是 红队) (Cybersecurity Red Team / Offensive Security Operations — the cognitive operating system of authorized red team operators, penetration testers, and offensive security consultants covering (a) reconnaissance & OSINT (passive + active discovery, asset surface mapping), (b) external network pentest (perimeter, exposed services, web), (c) internal network / Active Directory pentest (AD enumeration via BloodHound, Kerberos abuse — Kerberoasting / AS-REP-roasting / Unconstrained delegation / S4U2self, NTLM relay, ADCS abuse, GPO abuse, lateral movement, privilege escalation), (d) web application pentest (OWASP WSTG, authentication, authorization, SSRF, XXE, deserialization, SSTI, prototype pollution, GraphQL, JWT, API), (e) mobile pentest (OWASP MASTG, iOS / Android, instrumentation Frida / Objection, MASVS), (f) cloud pentest (AWS / Azure / GCP — IAM enumeration, privilege escalation paths, container escape, K8s RBAC, serverless), (g) C2 operations & post-exploitation (Cobalt Strike / Sliver / Mythic / Havoc, beacon ops, malleable profiles, OPSEC), (h) initial access & evasion (phishing infrastructure, payload development, AV / EDR evasion, BYOVD, AMSI / ETW bypass — strictly for authorized engagements), (i) wireless / RF (WPA2/3, evil twin, Wi-Fi pivots), (j) physical / social engineering (badge cloning, pretexting, vishing — under engagement letter), (k) reporting & remediation (executive summary, technical findings, CVSS, MITRE ATT&CK mapping, retest), (l) frameworks & methodology (MITRE ATT&CK, MITRE D3FEND, PTES, OSSTMM, NIST SP 800-115, OWASP WSTG / MASTG, Cyber Kill Chain, Unified Kill Chain, Diamond Model), (m) law & ethics (CFAA US, Computer Misuse Act UK, 中国 刑法 285/286 + 网络安全法 + 数据安全法, GDPR for tested EU systems, engagement letter, scope, rules of engagement, safe harbor for bug bounty); NOT criminal hacking / 黑产 / unauthorized targeting / mass exploitation / supply-chain compromise / DoS against unconsented systems (这是 重罪 + 业内开除 + 律师执照吊销, 本 skill 严守 authorized-only 边界), NOT pure defensive blue team / SOC analyst tradecraft (是 平行学科, 仅做 边界标注 + ATT&CK 反推方向), NOT malware-as-a-service development / botnet ops / ransomware authoring (是 cybercrime 不是 红队), NOT 'ethical hacking' 在 'just curious 看看' 自我合理化的灰色操作 (违反 authorization 原则即不是 红队).) Master OS — automated mastery of Cybersecurity Red Team / Offensive Security Operations — the cognitive operating system of authorized red team operators, penetration testers, and offensive security consultants covering (a) reconnaissance & OSINT (passive + active discovery, asset surface mapping), (b) external network pentest (perimeter, exposed services, web), (c) internal network / Active Directory pentest (AD enumeration via BloodHound, Kerberos abuse — Kerberoasting / AS-REP-roasting / Unconstrained delegation / S4U2self, NTLM relay, ADCS abuse, GPO abuse, lateral movement, privilege escalation), (d) web application pentest (OWASP WSTG, authentication, authorization, SSRF, XXE, deserialization, SSTI, prototype pollution, GraphQL, JWT, API), (e) mobile pentest (OWASP MASTG, iOS / Android, instrumentation Frida / Objection, MASVS), (f) cloud pentest (AWS / Azure / GCP — IAM enumeration, privilege escalation paths, container escape, K8s RBAC, serverless), (g) C2 operations & post-exploitation (Cobalt Strike / Sliver / Mythic / Havoc, beacon ops, malleable profiles, OPSEC), (h) initial access & evasi

日本語の概要は準備中です。原文の説明を表示しています。

swaylq/master-skill1492026年9月6日 更新

agent-skill-mapping

無料日本語概要

Skillの割当表(agent -> skills)を作るときのルール集。skill-assigner が mapping を更新するときに参照する。

diegosouzapw/awesome-omni-skill622026年3月2日 更新