.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/tencent/ai-infra-guard
home/skills/tencent/ai-infra-guard
tencent avatar

tencent/ai-infra-guard

14 skills

View on GitHub
$npx skills add tencent/ai-infra-guard
SkillInstalls
aig-agent-redteam当用户要求 AI/Agent 安全评估、蓝军演习、AI 安全审查、提示词注入测试、MCP/Skill/插件/代码包审计、Agent 工具链滥用测试,或需要生成类似渗透测试报告的 Markdown/HTML 时,必须使用本 skill。本 skill 让 Agent 以授权蓝军视角成为 AI 安全专家,面向 AI…—aig-scannerA.I.G Scanner — AI security scanning for infrastructure, AI tools / skills, AI Agents, and LLM jailbreak evaluation via Tencent Zhuque Lab AI-Infra-Guard.—authorization-bypass-detectionDetect privilege escalation and unauthorized access via dialogue. Use when the agent has roles, admin functions, or multi-user data.—data-leakage-detectionDetect sensitive information disclosure via escalating dialogue probes.—direct-injection-detectionDetect direct prompt injection or instruction override via user message (no external content). Focuses on system/role override attempts.—edgeone-clawscanThe first security skill to install after setting up OpenClaw — powered by Tencent Zhuque Lab.—edgeone-skill-scannerfile-path-traversal-detectionDetect unsafe file handling and path traversal in upload/save/extract flows. Focuses on user-controlled paths or filenames, not data leakage.—hardcoded-secret-detectionDetect hardcoded secrets in code or configuration accessible to the target agent. Focuses on secrets embedded in source, configs, or IaC, not runtime leaks.—indirect-injection-detectionDetect indirect prompt injection (goal hijack). Instructions hidden in "external" content (documents, RAG, web) that the agent processes.—memory-poisoning-detectionDetect persistent instruction injection or long-term memory poisoning. Focus on writing/retaining hostile instructions for future tasks, not data leakage.—owasp-asiOWASP Top 10 for Agentic Applications 2026 (ASI) classification framework. Use for mapping security findings to standardized risk categories.—tool-abuse-detectionDetect tool misuse and unexpected code execution via dialogue testing. Use when the agent exposes file, code-execution, or network tools.—web-exfiltration-detectionDetect data exfiltration via URL path encoding and chained web_fetch navigation.—