Malware Repo Analysis
恶意仓库分析技能,检测 GitHub 仓库中的恶意代码、供应链投毒与可疑 install 脚本,防范依赖混淆攻击。
Malware Repo Analysis is an Agent skill for Security. 恶意仓库分析技能,检测 GitHub 仓库中的恶意代码、供应链投毒与可疑 install 脚本,防范依赖混淆攻击。 Tags: 恶意代码 · malware · 安全 · security · 供应链 · supply-chain.
What is Malware Repo Analysis
Malware Repo Analysis packages a Security workflow for agents. 恶意仓库分析技能,检测 GitHub 仓库中的恶意代码、供应链投毒与可疑 install 脚本,防范依赖混淆攻击。
Install Malware Repo Analysis in Cursor / Claude / Codex
Claude Code Install with the command on this page, or place the skill in ~/.claude/skills or project .claude/skills so Claude can detect Malware Repo Analysis.
Cursor After the install command writes the skill directory, invoke Malware Repo Analysis by name in the Cursor agent.
Codex Install into the Codex skills directory and call it by name. If only a generic command is listed, run it locally and confirm Codex can see the skill.
One-click Install
Run the following command in your terminal to install the skill into your AI agent:
npx skillsadd obra/superpowersHow to Use
Claude Code: Place the skill in ~/.claude/skills (personal) or the project .claude/skills directory, and Claude will auto-detect it.
Cursor / Windsurf: After installing via npx skillsadd, the skill directory is placed in the configured path.
Codex CLI: After installation it loads automatically from the skills directory and is invoked by name.
Tags
Similar recommendations
Red Teaming
红队对抗测试技能,模拟攻击者视角对 AI 系统进行越狱、注入与信息泄露测试,发现并修补安全漏洞。
Git Guardrails
Git 安全护栏技能,防止向远程仓库推送密钥、令牌与敏感信息,支持预提交扫描与历史记录清理。
Source Verification
信息溯源与事实核查技能,交叉验证多方来源、检测虚假信息与幻觉,为 Agent 输出提供可信度评估。
GitHub Auth Management
GitHub 认证管理技能,安全配置 Personal Access Token、SSH 密钥与 GitHub App 权限,遵循最小权限原则。
WebApp Security Testing
Web 应用安全测试技能,检测 XSS、CSRF、SQL 注入与 SSRF 等 OWASP Top 10 漏洞并输出修复建议。
Web Research & QA
网络调研与质量保障技能,交叉验证搜索结果可信度、检测钓鱼链接与虚假信息,保障调研安全。
FAQ
What is Malware Repo Analysis for?
Malware Repo Analysis is a Security skill. 恶意仓库分析技能,检测 GitHub 仓库中的恶意代码、供应链投毒与可疑 install 脚本,防范依赖混淆攻击。
Can Claude, Cursor, and Codex all use Malware Repo Analysis?
Yes if the client supports Agent Skills and has loaded the skill directory. Check the project home for compatibility notes.
What similar skills exist?
Related items come from the same Security group so you can pick a closer workflow.