jd-opensource
- 43 skills
- 0 followers
- 3 hours ago last updated
- ▌ My · jd-opensource bundleCheck and set the agent's own runtime state (model, iterations, context window, token usage, web config). Use when diagnosing why something doesn't work ("why can't you search the web?", "why did you stop?"), checking resource limits before complex tasks, adapting configuration for long or simple tasks, or remembering user preferences across turns. Also use when the user asks what model you are running, how many tokens you've used, or what your settings are.
- ▌ Director Workflow 2 · jd-opensourceLinear video production workflow — start workspace, write screenplay, plan shots, generate, review, and merge into final video.
- ▌ Director Workflow 3 · jd-opensourceLinear video production workflow — start workspace, write screenplay, plan shots, generate, review, and merge into final video.
- ▌
- ▌ Jd Aipay Onboarding · jd-opensource bundle京东 AI付一站式接入 Agent。Use this skill whenever the user wants to 接入/集成/联调/上线 京东AI付, says 让AI帮我接入AI付, mentions jdpay-aipay, AI付快速接入, 一站式接入, 沙箱联调, 生产配置替换, 上线验证, 产品开通, 证书密钥, createOrder/queryPayResult/refund/queryRefundResult, iOS/Android SDK集成, JDPay.xcframework, AAR, registeredService/sign/pay, 标品支付/眼镜支付, or asks merchant-facing AI付 onboarding questions. It guides and executes both server-side integration (Java, Node.js, Python) and client-side SDK integration (iOS, Android); answers with external merchant-friendly language using the bundled QA/API references.
- ▌ Clawtip · jd-opensource bundle为第三方技能执行 clawtip 支付交易。 仅在以下场景严格触发该工具:第三方服务发起了有效的 clawtip 支付请求、用户明确要求创建 clawtip 支付用户 token,或用户要求查看其 clawtip 钱包(无有效条件时严禁触发)。 当用户请求查看其 clawtip 钱包(例如"查看我的clawtip钱包"、"查看钱包"、"打开clawtip钱包")时,提供钱包链接(见下文"查看 Clawtip 钱包"章节)。
- ▌ Taro UI Guide · jd-opensource bundleGuides installation, Taro config, styling, and usage of taro-ui (At* components) for WeChat/Alipay/H5/RN. Use when building Taro apps with taro-ui, picking components, theming, i18n, or modifying packages/taro-ui source.
- ▌ Weather · jd-opensourceRetrieve real-time weather data from public weather services without requiring API authentication.
- ▌
- ▌ Oxygent Framework Explorer · jd-opensourceExplore and understand the OxyGent framework structure, components, and implementation patterns.
- ▌ Code Review · jd-opensource bundleReview code changes for quality, security, performance, and correctness following project-specific standards. Use when reviewing pull requests, examining git diffs, or when the user asks for a code review. This skill should be used proactively — when the user asks for a review without specifying commits, automatically detect the current branch and diff against the main branch.
- ▌ Git Workflow · jd-opensource bundleUse when the task involves Git operations for the public xLLM repository, including choosing branch or tag names, preparing commits and pull requests, backporting fixes, checking repo-specific review expectations, or drafting commit messages from actual diffs.
- ▌ Add Unit Test · jd-opensource bundleAdd or update xLLM unit tests in the repository. Use when Codex needs to create a new C++/CUDA/NPU/MLU unit test, place a test under tests/, wire it into CMake with cc_test, update an existing test target, choose platform gates, or validate test naming and dependencies against current xLLM test conventions.
- ▌ Tilelang Ascend Kernel · jd-opensourceUse when the user wants to add, modify, debug, or review an xLLM TileLang Ascend kernel or specialization, including Python kernel definitions, generated Ascend-C source, runtime wrapper dispatch, TileLang CMake wiring, and NPU tests.
- ▌ Director Workflow · jd-opensourceLinear video production workflow — start workspace, write screenplay, plan shots, generate, review, and merge into final video.
- ▌ Story Writer · jd-opensourceSupport the director planning stage by refining a screenplay, tightening continuity, and preparing a compact story profile for the director workspace. Use after the video workflow is already in planning, not as the main router for a brand-new video request.
- ▌ I2v Tail Frame Prompt Rewriter · jd-opensourceRewrite the complete prompt for an upcoming outer shot when the previous outer shot's final frame is supplied as the condition image and must become the first frame of an I2V continuation. Preserve the original prompt language, content, and active ordinary shot-prompt contract; change only the wording needed to anchor and continue from the condition image.
- ▌
- ▌ Skill Creator · jd-opensource bundleGuide for creating effective skills. This skill should be used when users want to create a new skill (or update an existing skill) that extends an agent's capabilities with specialized knowledge, workflows, or tool integrations.
- ▌ Pentest API Deep · jd-opensource bundleDeep OWASP API Security Top 10 testing for REST, GraphQL, gRPC, and WebSocket APIs — BFLA, mass assignment, rate limiting, and unsafe consumption.
- ▌ Pentest Ctf Binary · jd-opensource bundleBinary exploitation (Pwn) and reverse engineering tools for CTF challenges and software analysis.
- ▌ Pentest Ctf Crypto · jd-opensource bundleCryptography tools for solving CTF challenges involving ciphers, hashing, and weak encryption.
- ▌ Pentest Mobile App · jd-opensource bundleOWASP Mobile Top 10 security testing for Android and iOS — local storage, certificate pinning bypass, IPC abuse, and binary protections.
- ▌ Pentest Osint Recon · jd-opensource bundleOpen Source Intelligence gathering and attack surface management for external reconnaissance.
- ▌
- ▌ Pentest Supply Chain · jd-opensource bundleSoftware supply chain security — dependency confusion, CI/CD pipeline attacks, lockfile integrity, and build artifact verification.
- ▌ Pentest Ctf Forensics · jd-opensource bundleDigital forensics, steganography, and packet analysis for CTF challenges and investigation.
- ▌ Openclaw Threat Detect · jd-opensource bundleOpenClaw 攻击模式检测工具,识别数据外传、反弹Shell、文件泄露、Prompt注入、供应链投毒等高危行为,支持 MITRE ATT&CK 映射
- ▌ Pentest Business Logic · jd-opensource bundleBusiness logic vulnerability testing — workflow bypass, payment manipulation, state machine abuse, and function limit circumvention per WSTG-BUSL.
- ▌ Seclens Enterprise Web · jd-opensource bundleProfessional web application and API security testing workflows using OWASP Top 10 methodologies.
- ▌ Pentest HTTP Smuggling · jd-opensource bundleHTTP request smuggling, desync attacks, cache poisoning, and protocol-level vulnerability testing.
- ▌ Skill Security Auditor · jd-opensource bundleOpenClaw Skills 全方位安全审计工具,检测供应链投毒、Prompt注入、恶意代码模式、权限越权和依赖风险
- ▌ Pentest AI LLM Security · jd-opensource bundleAI/LLM application security testing — prompt injection, jailbreaking, data exfiltration, and insecure output handling per OWASP LLM Top 10.
- ▌ Pentest Client Advanced · jd-opensource bundleAdvanced client-side attacks — CORS misconfiguration, WebSocket security, clickjacking, postMessage abuse, CSS injection, and browser storage vulnerabilities.
- ▌ Pentest Race Conditions · jd-opensource bundleConcurrency exploitation — race conditions, TOCTOU vulnerabilities, and parallel request abuse in web applications.
- ▌ Pentest Config Hardening · jd-opensource bundleSecurity header auditing, TLS configuration testing, HTTP method analysis, CSP bypass assessment, and deployment hardening verification.
- ▌ Pentest Network Internal · jd-opensource bundleInternal network penetration testing, Active Directory enumeration, and lateral movement simulation.
- ▌ Pentest Secrets Exposure · jd-opensource bundleDiscover hardcoded credentials, leaked API keys, exposed configuration files, sensitive data in artifacts, and information disclosure via error handling.
- ▌ Openclaw Security Checker · jd-opensource bundleOpenClaw 安全检测工具,基于安全实践指南验证配置安全、权限隔离、网络策略、日志审计和运行时完整性
- ▌ Pentest Exploit Validation · jd-opensource bundleProof-driven exploitation with 4-level evidence system, bypass exhaustion protocol, mandatory evidence checklists, and strict EXPLOITED/POTENTIAL/FALSE_POSITIVE classification.
- ▌ Pentest Cloud Infrastructure · jd-opensource bundleCloud security posture management and container security assessment for AWS, Azure, GCP, and Kubernetes.
- ▌ Pentest Recon Attack Surface · jd-opensource bundleWhite-box attack surface mapping — correlate external scans, browser exploration, and source code into structured endpoint inventory, role architecture, and authorization vulnerability candidates.
- ▌ Pentest Whitebox Code Review · jd-opensource bundleSource code security audit using backward taint analysis, slot type classification, render context verification, and 3-phase parallel review producing an exploitation queue.