---
title: "Tencent (@tencent) skills · skilld"
canonical_url: "https://skilld.dev/gh/tencent"
meta:
  description: "23 agent skills published by Tencent on skilld."
  "og:description": "23 agent skills published by Tencent."
  "og:title": "Tencent on skilld"
---

`

![Avatar for Tencent](https://skilld.dev/_img/avatar?url=https%3A%2F%2Fgithub.com%2Ftencent.png)

# **Tencent**

[@tencent](https://github.com/tencent)org

23 skills3 repos 31k Shenzhen, China

[GitHub](https://github.com/tencent) [Website](https://opensource.tencent.com)

## Skills

### [tencent/ai-infra-guard](https://skilld.dev/gh/tencent/ai-infra-guard)

19 skills 6.7k

`npx skilld add tencent/ai-infra-guard`

- [

  **/agentic-supply-chain-detection**6.7k

  Detect agentic supply-chain risks: compromised dependencies, malicious plugins/tools/models, and untrusted update sources. /agentic-supply-chain-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/agentic-supply-chain-detection)
- [

  **/aig-agent-redteam**6.7k

  当用户要求 AI/Agent 安全评估、蓝军演习、AI 安全审查、提示词注入测试、MCP/Skill/插件/代码包审计、Agent 工具链滥用测试，或需要生成类似渗透测试报告的 Markdown/HTML 时，必须使用本 skill。本 skill 让 Agent 以授权蓝军视角成为 AI 安全专家，面向 AI 产品、Agent、MCP Server、Skill、代码仓库和 AI 基础设施进行安全演习。优先使用第一性原理推理和真实证据，而不是机械跑 payload 库；脚本只用于 HTTP 指纹识别、证据聚合、报告渲染等确定性辅助任务。 /aig-agent-redteam by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/aig-agent-redteam)
- [

  **/aig-scanner**6.7k

  A.I.G Scanner — AI security scanning for infrastructure, AI tools / skills, AI Agents, and LLM jailbreak evaluation via Tencent Zhuque Lab AI-Infra-Guard. Uses built-in exec + Python script, no plugin required. Requires AIG\_BASE\_URL to be configured. Triggers on: scan AI service, AI vulnerability scan, scan AI infra, check CVE, audit AI service, scan MCP, scan skills, audit AI tools, scan agent, red-team LLM, jailbreak test, 扫描AI服务, 检查AI漏洞, 扫描AI工具, 检查MCP安全, 审计Agent, 越狱测试. /aig-scanner by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/aig-scanner)
- [

  **/authorization-bypass-detection**6.7k

  Detect privilege escalation and unauthorized access via dialogue. Use when the agent has roles, admin functions, or multi-user data. /authorization-bypass-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/authorization-bypass-detection)
- [

  **/cascading-failure-detection**6.7k

  Detect error propagation, chain failures, and single-point breakdowns that cascade across agent workflows. /cascading-failure-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/cascading-failure-detection)
- [

  **/data-leakage-detection**6.7k

  Detect sensitive information disclosure via escalating dialogue probes. Covers system prompt extraction, credential/API key leakage, PII, and internal configuration exposure. /data-leakage-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/data-leakage-detection)
- [

  **/direct-injection-detection**6.7k

  Detect direct prompt injection or instruction override via user message (no external content). Focuses on system/role override attempts. /direct-injection-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/direct-injection-detection)
- [

  **/edgeone-clawscan**6.7k

  The first security skill to install after setting up OpenClaw — powered by Tencent Zhuque Lab. Works like an antivirus for your AI environment: audits installed skills, scans skills before installation, and performs a full OpenClaw security health check to prevent data leaks and privacy risks. Backed by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). Use when the user asks to start a security health check or security scan for the current OpenClaw environment, such as \`开始安全体检\`, \`做一次安全体检\`, \`开始安全扫描\`, \`全面安全检查\`, or \`检查 OpenClaw 安全\`; also use when the user asks to audit a specific skill before installation, review installed skills for supply chain risk, or investigate whether a skill is safe. Do not trigger for general OpenClaw usage, project debugging, environment setup, or normal development requests. Optional cloud mode: set AIG\_CLOUD\_LOOKUP=off for zero outbound HTTPS; when enabled, only skill\_name, source label, and OpenClaw version are sent to A.I.G (never skill bodies, chats, or workspace files). /edgeone-clawscan by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/edgeone-clawscan)
- [

  **/edgeone-skill-scanner**6.7k

  Scan any agent skill for security risks before you install or use it. Powered by Tencent Zhuque Lab A.I.G (AI-Infra-Guard). 100% local static analysis — no file contents or credentials leave your device. Compatible with CodeBuddy, Cursor, Windsurf, Claude Code, OpenClaw and more. Triggers on: \`这个 skill 安全吗\`, \`skill 安全扫描\`, \`检查 skill 安全\`, \`audit skill\`, \`scan skill\`, \`check skill safety\`, \`analyze skill\`, \`inspect skill\`, \`verify skill\`, \`skill security\`, \`skill supply chain\`. Do NOT trigger for general agent usage, full system health checks, project debugging, or normal development. /edgeone-skill-scanner by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/edgeone-skill-scanner)
- [

  **/file-path-traversal-detection**6.7k

  Detect unsafe file handling and path traversal in upload/save/extract flows. Focuses on user-controlled paths or filenames, not data leakage. /file-path-traversal-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/file-path-traversal-detection)
- [

  **/hardcoded-secret-detection**6.7k

  Detect hardcoded secrets in code or configuration accessible to the target agent. Focuses on secrets embedded in source, configs, or IaC, not runtime leaks. /hardcoded-secret-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/hardcoded-secret-detection)
- [

  **/human-agent-trust-exploit-detection**6.7k

  Detect social engineering, deceptive responses, false assurances, or prompts that induce unsafe user actions. /human-agent-trust-exploit-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/human-agent-trust-exploit-detection)
- [

  **/indirect-injection-detection**6.7k

  Detect indirect prompt injection (goal hijack). Instructions hidden in "external" content (documents, RAG, web) that the agent processes. Use when the agent has document/RAG/web/file input. /indirect-injection-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/indirect-injection-detection)
- [

  **/inter-agent-comm-security-detection**6.7k

  Detect data leakage, missing boundaries, or privilege mismatch in inter-agent communication. /inter-agent-comm-security-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/inter-agent-comm-security-detection)
- [

  **/memory-poisoning-detection**6.7k

  Detect persistent instruction injection or long-term memory poisoning. Focus on writing/retaining hostile instructions for future tasks, not data leakage. /memory-poisoning-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/memory-poisoning-detection)
- [

  **/owasp-asi**6.7k

  OWASP Top 10 for Agentic Applications 2026 (ASI) classification framework. Use for mapping security findings to standardized risk categories. /owasp-asi by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/owasp-asi)
- [

  **/tool-abuse-detection**6.7k

  Detect tool misuse and unexpected code execution via dialogue testing. Use when the agent exposes file, code-execution, or network tools. /tool-abuse-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/tool-abuse-detection)
- [

  **/unexpected-code-execution-detection**6.7k

  Detect command injection, eval/exec usage, remote execution, or arbitrary code loading. /unexpected-code-execution-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/unexpected-code-execution-detection)
- [

  **/web-exfiltration-detection**6.7k

  Detect data exfiltration via URL path encoding and chained web\_fetch navigation. Covers fake trusted UI injection, letter-level URL path exfiltration, and multi-hop navigation hijacking. Use when the agent has web/URL fetch capability and stores user memory or personal context. /web-exfiltration-detection by tencent](https://skilld.dev/gh/tencent/ai-infra-guard/web-exfiltration-detection)

### [tencent/weknora](https://skilld.dev/gh/tencent/weknora)

3 skills 31k

`npx skilld add tencent/weknora`

- [

  **/pdf-processing**31k

  Extract text and tables from PDF files, fill forms, merge documents. Use when working with PDF files or when the user mentions PDFs, forms, or document extraction. /pdf-processing by tencent](https://skilld.dev/gh/tencent/weknora/pdf-processing)
- [

  **/weknora-rag-search**31k

  Use when retrieving from or asking questions against a WeKnora knowledge base via the \`weknora\` CLI — and especially when unsure whether to use \`chat\`, \`session ask\`, or \`search chunks\` for a given goal. /weknora-rag-search by tencent](https://skilld.dev/gh/tencent/weknora/weknora-rag-search)
- [

  **/weknora-shared**31k

  Use when driving a WeKnora RAG server through the \`weknora\` CLI as an agent — authenticating, managing knowledge bases / documents / sessions / agents, running search or chat, or interpreting the CLI's JSON envelopes and exit codes. Read this before any other weknora-\* skill. /weknora-shared by tencent](https://skilld.dev/gh/tencent/weknora/weknora-shared)

### [tencent/browserskill](https://skilld.dev/gh/tencent/browserskill)

1 skill 8k

`npx skilld add tencent/browserskill`

- [

  **/skill**8k

  Automate the user's logged-in Chromium browser: read pages, fill forms, scrape data, operate tabs, test a UI, or debug a website. Requires the bsk CLI and browser extension. /skill by tencent](https://skilld.dev/gh/tencent/browserskill)

Skills published by Tencent. Checked GitHub just now