← All creators

goingli0324

User

Claude Code skill: defensive security review of your own code (Apps Script, frontend, backend)

18 indexed · 0 Featured · 4 stars · avg score 71
Prolific

Categories

Indexed Skills (18)

Web & Frontend Listed

web-security-reviewer

對使用者自己的程式碼做防禦性安全審查,檢測資安漏洞、資料外洩風險、壓力/效能風險與程式品質,並產出「依嚴重度排序的風險報告 + 修正後程式碼」。涵蓋 Google Apps Script(Workspace 自動化)、前端 HTML/CSS/JS、後端 API(Node/Python/PHP 等)。特別適用於「使用者用 AI 生成 / vibe coding 寫出來、希望更安全、避免被攻擊或破壞」的網頁程式碼。MANDATORY TRIGGERS:使用者要求「檢測程式碼安全」「幫我看這段 code 有沒有漏洞」「防止資料外洩」「review 我的網頁/後端程式」「這段會不會被攻擊/被駭」「加固 / harden」「壓力測試」「優化程式碼安全性」「個資會不會外洩」「這是 AI 寫的幫我看安不安全」,或貼上一段前端/後端/Apps Script 程式碼並要求審查、找漏洞、修正建議、加固時,都要套用此 skill。即使使用者沒明說「資安」,只要意圖是審查或加固自己的程式碼,就觸發。SCOPE:本 skill 僅用於防禦性檢測——找出並修補使用者自己程式碼裡的漏洞;不協助撰寫可直接攻擊用的 exploit、不協助繞過資安機制。本 skill 同時是 agentic-dev-loop「Verify 雙閘」的安全閘:當該編排器要在部署前驗證安全/個資時會呼叫本 skill;使用者單獨要求安全審查時仍直接觸發本 skill。

4 Updated 1 weeks ago
goingli0324
AI & Automation Listed

agentic-dev-loop

從研究、plan.md、實作、Verify 雙閘到部署的開發迴圈編排器。當使用者要有計畫地把一個功能或 bug 從規劃走到上線(「開一個新功能」「先研究再做」「整理成 plan.md」「從頭做到上線」「幫我排開發步驟」「<專案名> 要加…」),或提出未指明範圍的「部署前/上線前檢查」時觸發——後者一律走雙閘,只跑 UI/UX 會漏掉安全與個資驗證。明確只要 UI/UX、只要安全審查、或只要分析連動禁區時,改用對應的單一 skill。

0 Updated yesterday
goingli0324
Code & Development Listed

web-security-reviewer

對使用者自己的程式碼做防禦性安全審查,輸出依嚴重度排序的風險報告與修正後程式碼。當使用者要找漏洞、加固、擔心被攻擊或個資外洩,或貼上一段 AI 生成的程式碼要人幫忙看安不安全時觸發。也是 agentic-dev-loop Verify 雙閘的安全閘,供其他 skill 呼叫。

0 Updated yesterday
goingli0324
Data & Documents Listed

futures-studies-analyst

以 Inayatullah 六大支柱整合的未來學方法(Delphi、CLA、情境規劃、趨勢與環境掃描、未來三角、未來輪、浮現議題、回推分析、超越法、Three Horizons、Cross-Impact)分析原始資料,產出結構化分析或思考鷹架。當使用者提供專家意見、訪談逐字稿、座談紀錄、政策趨勢資料或自己的分析草稿,要求用未來學方法分析、指名其中某個方法、或說「這批資料看不出結構」時觸發。要的是可貼入論文的學術段落時改用 phd-edu-futures-writer。

0 Updated yesterday
goingli0324
Code & Development Listed

pdca-process-review

用 PDCA(戴明循環)檢視與優化任何反覆執行的流程。當使用者提到 PDCA/戴明循環/Deming cycle,要求流程復盤或持續改善,或描述一個自己反覆在做、但成效不如預期或執行起來很亂的流程並想找出卡點時觸發。不限領域,但檢視的是流程,不是單一決策。

0 Updated yesterday
goingli0324
AI & Automation Listed

futures-studies-analyst

以 Inayatullah 六大支柱框架(測繪、預期、定時、深化、另創、轉化)整合的未來學研究方法——Delphi 法、CLA 因果層次分析(含四象限地圖)、情境規劃 Scenario Planning(五種情境建構法,含 CLA 內建情境矩陣)、趨勢分析與環境掃描、未來三角與未來景緻、未來輪、浮現議題分析、拆解重組法、回推分析、超越法、Three Horizons、Cross-Impact Analysis——分析使用者提供的原始資料,並產出結構化分析或思考鷹架。MANDATORY TRIGGERS:當使用者提供 Delphi 問卷回收的專家意見/文字回饋、訪談逐字稿、焦點座談紀錄、新聞政策產業趨勢資料、或自己的分析草稿,並要求「用未來學方法分析」「幫我做 Delphi 分析」「跑一下 CLA」「建構情境」「掃描趨勢」「未來輪」「未來三角」「六大支柱」「三層次分析」「回推分析」「拆解重組」「超越法」「這批資料看不出結構,幫我看」時,必須觸發本 skill。即使使用者沒有指名特定方法,只要意圖是「把一批質性或趨勢資料轉換成未來學分析結構」,就要主動判斷合適方法並觸發,不需使用者明說方法名稱。若使用者提供的是錄音檔且尚無逐字稿,本 skill 也負責判斷並提醒轉錄步驟。此 skill 專注於「分析資料」本身;把分析結果寫成可直接投稿或貼入論文的學術段落,屬於後續的學術寫作階段,不在本 skill 範圍。

0 Updated 3 days ago
goingli0324
Code & Development Listed

pdca-process-review

用 PDCA(Plan-Do-Check-Act,戴明循環)系統性檢視���優化任何反覆執行的流程或工作方式。當使用者要求「用 PDCA 檢視/分析/優化某個流程」「這個流程哪裡卡住、怎麼改善」「幫我做一次流程復盤」「持續改善」,或提到 PDCA、戴明循環、Deming cycle、Plan-Do-Check-Act 等詞彙時,務必觸發。也要主動用於這種情境:使用者描述一個自己反覆在做、但成效不如預期或執行起來很亂的流程(不論是研究方法執行、教學/評審工作、行政作業、專案管理、還是個人習慣),想要找出問題根源並規劃下一步調整——即使對方沒有講出「PDCA」這個詞。不限定領域,適用任何重複性流程的檢視與優化。

0 Updated 3 days ago
goingli0324
AI & Automation Listed

agentic-dev-loop

系統化開發工作流,把「先研究 → 寫 plan.md → 依計畫實作 → 部署前雙閘驗證 → 部署」固定成一條可重複的迴圈,專為單人維護多個 Firebase / Google Apps Script / GCP Cloud Run 專案的情境設計。核心是「計畫先行、狀態外部化到檔案、依專案風險分級決定授權與驗證強度」,作為編排器串接三個既有 skill:進入專案前若尚未建立連動禁區 → project-guardrails 分析並寫入 CLAUDE.md,規劃時據以避開「改 A 壞 B」;部署前 Verify 雙閘 → web-security-reviewer 做安全/個資/壓力驗證、ui-ux-deploy-reviewer 做 UI/UX 與呈現層審查(僅當有前端介面)。MANDATORY TRIGGERS:使用者說「開一個新功能」「幫我規劃這個開發」「從頭把這個功能做到上線」「先研究再做」「整理成 plan.md」「這個專案要怎麼做(指要從規劃做到上線,不是單純問方向)」「修這個 bug(要有計畫地修)」「<專案名> 要加東西」(以專案名開頭的開發需求)「要部署到 Firebase / Cloud Run」「GAS 寫一個…」「我有個想法想做成���具」「幫我排開發的步驟」「走完整個開發到部署的流程」,或貼上 issue 連結、錯誤截圖、需求描述並希望有系統地把它從規劃做到上線時,都要套用此 skill。注意分流:若使用者只要「單獨檢查 UI/UX」用 ui-ux-deploy-reviewer、只要「單獨做安全審查」用 web-security-reviewer、只要「分析專案禁區」用 project-guardrails;本 skill 是把這些串成完整迴圈的編排器,當意圖是「有規劃、可重現、會走到上線」的整段開發時才觸發。**重要安全防漏:若使用者說的是泛泛的「部署前檢查」「上線前幫我檢查」而沒指明只要 UI/UX 或只要安全,應由本 skill 接手走 Verify 雙閘(同時跑 web-security-reviewer 與 ui-ux-deploy-reviewer),絕不要只做其中一道——尤其不要只做 UI/UX 而漏掉安全閘,那會讓含學生個資的專案在沒過安全驗證下就上線。**SCOPE:本 skill 是工作流編排器,不取代使用者對計畫的閱讀與判斷;只在使用者自己的專案上運作,不協助繞過授權

0 Updated 6 days ago
goingli0324
AI & Automation Listed

ai-roleplay-practice

Sets up an interactive AI roleplay so the user can rehearse a difficult conversation — any persona they name — with structured feedback at the end. Use when the user says 「讓AI扮演…」「陪我練習…」「模擬一下…情境」, or wants to rehearse before a high-stakes interaction (a skeptical parent, a dissertation committee, an interviewer, a negotiation counterpart).

0 Updated yesterday
goingli0324
Testing & QA Listed

multi-perspective-panel

Reviews a decision, plan, or open question from four independent angles — critical, creative, communication, interaction — as a parallel panel or a red-team/blue-team debate. Use when the user asks 「從多角度想」「組隊思考」「壓力測試這個決定」, brings a plan they want checked for blind spots, or is doing scenario/strategy work (including CLA or futures scenarios) that needs more than one lens.

0 Updated yesterday
goingli0324
AI & Automation Listed

project-guardrails

分析專案程式碼,找出「改 A 會壞 B」的連動禁區——高扇入模組、資料結構契約、部署設定、對外契約、演算法核心——經確認後寫入該專案的 CLAUDE.md。當使用者要建立 guardrails、問哪些程式碼不能亂動、哪些模組牽一髮動全身時觸發。也是 agentic-dev-loop Step 0 的前置階段。

0 Updated yesterday
goingli0324
AI & Automation Listed

prompt-coach

Turns a vague ask into a Goal / Constraints / Obstacle breakdown, then a ready-to-use structured prompt. Use when the user brings a fuzzy request (「幫我想辦法…」「有什麼方法可以…」「我不知道怎麼處理…」), asks to 「問對問題」, or names a real problem without saying what success looks like, what can't change, or what the blocker is.

0 Updated yesterday
goingli0324
Web & Frontend Listed

ui-ux-deploy-reviewer

以 20 項 UI/UX 原則(Nielsen 啟發法+互動心理學定律+可及性)審視前端程式碼與使用者體驗,輸出依嚴重度排序的問題清單與部署放行檢核表。當使用者明確要審查 UI/UX、易用性、heuristic evaluation,或問「這個網站好不好用」時觸發;未指明範圍的「部署前檢查」交給 agentic-dev-loop 走雙閘。也是該迴圈的 UI/UX 閘。

0 Updated yesterday
goingli0324
Web & Frontend Listed

ui-ux-deploy-reviewer

部署前的 UI/UX 總體檢。以全球公認的 20 項 UI/UX 原則(Nielsen 十大易用性啟發法 + 互動心理學定律 + 可及性與適應性)逐項審視網站或 Web App 的前端程式碼與使用者體驗,輸出「依嚴重度排序的問題清單 + 修正建議 + 部署放行檢核表」。MANDATORY TRIGGERS:使用者說「部署前 UI/UX 檢查」「deploy 前跑一次 UI/UX」「上線前幫我檢查 UI/UX」「審查 UI/UX」「用 20 原則檢視」「這個網站好不好用」「易用性審查」「heuristic evaluation」「檢查使用者體驗」,或在準備 firebase deploy / 上線 / 發布前要求做最後檢查時,都要套用此 skill。即使使用者沒明說「UI/UX」,只要意圖是部署前對介面與體驗做整體審視,就觸發。SCOPE:本 skill 審查 UI/UX 與呈現層程式碼品質;資訊安全審查請改用 web-security-reviewer。本 skill 同時是 agentic-dev-loop「Verify 雙閘」的 UI/UX 閘。分流原則:泛泛的「部署前/上線前檢查」(未指明只要 UI/UX)應交給 agentic-dev-loop 走雙閘,以免漏掉安全審查;本 skill 只在意圖明確聚焦 UI/UX/易用性/20 原則時觸發。

0 Updated 6 days ago
goingli0324
AI & Automation Listed

project-guardrails

為專案建立「連動禁區」防護段落。自動分析專案程式碼,找出高扇入模組、資料結構契約、部署設定、對外契約與演算法核心等「改 A 會壞 B」的高風險區域,經使用者確認後寫入該專案的 CLAUDE.md,作為日後所有修改行為的防護依據。MANDATORY TRIGGERS:使用者說「建立連動禁區」「設定 guardrails」「init guardrails」「幫這個專案建立防護」「分析哪些程式碼不能亂動」「哪些模組牽一髮動全身」「建立修改防護段落」「把禁區寫進 CLAUDE.md」,或在新專案開始前要求建立修改安全機制時,都要套用此 skill。適用於 Firebase/PWA、GAS、後端服務等各類專案。SCOPE:本 skill 只做分析與(經確認後的)CLAUDE.md 寫入,不修改任何程式碼。本 skill 同時是 agentic-dev-loop 開發迴圈的「前置」階段:當該編排器在 Step 0 發現專案尚未建立連動禁區時會呼叫本 skill;使用者單獨要求分析禁區時仍直接觸發本 skill。

0 Updated 6 days ago
goingli0324
AI & Automation Listed

ai-roleplay-practice

Sets up an interactive AI roleplay so the user can rehearse a difficult conversation or scenario — any persona, any context — with structured feedback at the end. Use this whenever the user wants to practice, rehearse, or prepare for a conversation by having AI play a specific role (a difficult student, a skeptical parent, a colleague pushing back, a dissertation committee member, an interviewer, a negotiation counterpart, or any other identity the user names), says things like "讓AI扮演...", "陪我練習...", "模擬一下...情境", or wants a safe, repeatable space to rehearse before a real high-stakes interaction. The persona is never fixed to one category — always let the user define who AI plays, and offer example personas only as starting suggestions.

0 Updated 6 days ago
goingli0324
Testing & QA Listed

multi-perspective-panel

Reviews any decision, plan, proposal, or open question from four independent thinking angles — critical, creative, communication, and interaction — either as a parallel panel or as an adversarial red-team/blue-team debate. Use this whenever the user asks to "從多角度想", "組隊思考", "壓力測試這個決定", brings a decision or plan and wants it reviewed for blind spots, is stuck seeing a problem from only one angle, or is doing scenario/strategy analysis (including dissertation-level CLA or futures-scenario work) that would benefit from multiple independent lenses rather than a single take. Trigger proactively even without the user naming the skill — any single-angle answer to a real decision or plan is a missed opportunity to surface blind spots the user can't see from where they're standing.

0 Updated 6 days ago
goingli0324
AI & Automation Listed

prompt-coach

Turns a vague, underspecified request into a clearly structured Goal / Constraints / Obstacle breakdown, then produces a ready-to-use structured prompt. Use this whenever the user brings a fuzzy ask ("幫我想辦法...", "有什麼方法可以...", "我不知道怎麼處理..."), asks explicitly to help them "問對問題" or structure their request, or describes a real-world problem/decision they want AI help with but haven't yet specified what success looks like, what can't change, or what the actual blocker is. Trigger this proactively — even without the user naming the skill — any time answering directly would likely produce a generic, "technically correct but not actually usable" answer rather than something tailored to their real situation.

0 Updated 6 days ago
goingli0324

Bio shown is the top-scored skill's repo description as a fallback — real GitHub bios land in a future update.