JD.com
Official@jd-opensource · China
JD Open Source
Agent Skills by JD.com
Showing 28 vetted skills indexed across 1 GitHub repositories.
planning-with-files
Maintain task_plan.md, findings.md, and progress.md to orchestrate long-running tasks.
pentest-mobile-app
Automate Android and iOS mobile app security testing with Frida and MobSF.
pentest-api-deep
Enumerate and test REST, GraphQL, gRPC, and WebSocket APIs for security weaknesses.
pentest-config-hardening
Audit HTTP security headers, TLS settings, and CSP policies across web assets.
seclens-enterprise-web
Coordinate OWASP Top 10 vulnerability assessments on web applications and APIs.
pentest-secrets-exposure
Detect hardcoded credentials and exposed secrets in source code and artifacts.
pentest-business-logic
Identify and test business logic vulnerabilities in web applications and APIs.
pentest-network-internal
Simulate attacker discovery, credential testing, and Active Directory mapping in internal networks.
pentest-ai-llm-security
Identifies and exploits AI/LLM security vulnerabilities in enterprise deployments using Garak and Burp Suite workflows.
xlsx
Automates spreadsheet creation, editing, analysis, and recalculation using OpenPyXL and Pandas.
Extract text and tables from PDFs using Python libraries.
executing-plans
Execute plan tasks in batches with review checkpoints and verification reports.
pentest-ctf-binary
Analyze binary files to identify memory corruption vulnerabilities and develop exploits.
pentest-client-advanced
Assess client-side security weaknesses across CORS, WebSocket, clickjacking, postMessage, CSS injection, and storage.
pentest-vuln-verify-test
Send raw HTTP requests to verify open redirects and XSS vulnerabilities.
pentest-osint-recon
Gather public OSINT data to map external attack surfaces.
skill-creator
Create modular Claude Skills with templated SKILL.md and resource scaffolding.
pptx
Create, edit, and analyze PowerPoint presentations with pptxgenjs and Playwright.
pentest-ctf-forensics
Identify and extract artifacts from memory dumps, PCAPs, and disk images.
brainstorming
Guide collaborative questioning to turn raw ideas into structured design concepts.
pentest-ctf-crypto
Identify cryptographic weaknesses and execute attacks across CTF challenges.
writing-plans
Generate structured implementation plans with tasks, files, and tests.
pentest-cloud-infrastructure
Automate cloud and container security assessments across AWS, Azure, GCP, and Kubernetes.
pentest-exploit-validation
Validate security findings through proof-driven exploitation with a four-level evidence system.
Frequently Asked Questions About JD.com
FAQPage SchemaWhat specific security tasks can be performed using these capabilities?▼
These capabilities enable end-to-end security assessments, including mobile application pentesting, cloud infrastructure hardening, supply chain dependency auditing, and binary memory corruption analysis. You can perform deep API enumeration, validate race conditions, and execute proof-driven exploit verification across diverse enterprise environments.
Which technical personas benefit most from these security modules?▼
Security engineers, penetration testers, and DevSecOps professionals are the primary users. These modules support technical teams tasked with mapping external attack surfaces, conducting whitebox code reviews, and performing forensic analysis on memory dumps or network traffic captures.
What are the core prerequisites for deploying these security assessments?▼
Deployment requires a configured environment capable of executing modular security tasks, typically involving access to target infrastructure, source code repositories, and necessary security testing frameworks like Frida, MobSF, or Garak. Users must ensure appropriate authorization and scope definitions are established before initiating network or application-level testing.