
Automated OWASP Top 10 security audit with severity ratings, CWE mappings, and remediation code.

Defensive application-security auditing: turns a repo, manifest, or code snippet into an actionable report—dependency vulnerabilities, leaked secrets, insecure code patterns, and config hardening—mapped to OWASP Top 10 and ranked by severity. Finds risk and the fix only, never attack content.

A scan tells you what is wrong. This tells you what to do. Same engine as the ADA Website Risk Scanner — 14 WCAG 2.2 AA check families. But instead of a defect list, you get a work plan: findings grouped into batches, ordered by exposure reduced per hour of developer time, each with before/after code, effort estimate, required skill, and a verification step. Three phases. Quick wins first. A project manager can assign it as-is.

A site architecture and internal linking tool for SaaS, e-commerce, content, docs, local, and subscription sites, designed for new builds, restructures, and SEO audits. Accepts a sitemap, page list, GSC errors, or a simple description. It produces a full structure audit, hierarchy plan, and internal linking recommendations. Orphan pages, misplaced URLs, and weak depth structures are detected, while GSC signals are translated into clear fixes that improve crawlability and help key pages surface.

提供一個網頁和目標客群,找出最影響 Google 與 AI 理解的問題,列出最多 5 個優先修改,並產生可直接使用的標題、網站描述與首屏文案。不亂猜排名。

Built from real-world Linux administration and security hardening experience. This skill focuses on practical Debian and Ubuntu server security reviews for self-hosters, system administrators and small businesses. Instead of making risky automatic changes, it identifies security issues, explains their impact and provides clear, actionable hardening recommendations.

Academic sanity-check with interactive HTML dashboard. Detects look-ahead bias, over-parameterization, and benchmarks against 10 canonical blueprints via animated SVG gauges and color-coded KPI cards. Parses natural language, code, or CSV uploads. Output auto-adapts (EN/ZH-TW/ZH-CN). Built on De Prado (2018). For students and strategy developers. Not financial advice.

This is the scoring reference the agent uses to turn raw crawl/API data into prioritized findings. Keep this file as the single source of truth — update it whenever a real audit reveals a false positive or a missing check. Scope covered: Crawlability & Indexation, Performance (Core Web Vitals), Structure & Markup. (Mobile/Architecture can be added in a later version.)
