js-analysis
Extract client-side attack surface from JS and sourcemaps without dictating the order of investigation.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
القائمة
Extract client-side attack surface from JS and sourcemaps without dictating the order of investigation.
التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.
استنادا إلى تصنيف SOC المهني
Four-phase autonomous bug bounty orchestration. Phase 0 maps external assets with deterministic Python helpers, Phase 1 lets AI prioritize attack surfaces, Phase 2 gives AI autonomous attack control, and Phase 3 produces verifier-only reports.
Four-phase autonomous bug bounty workflow. Python handles deterministic collection and verifier support; AI owns prioritization, attack reasoning, and autonomous direction changes.
Report generation agent. Convert verifier-confirmed findings into a fixed evidence-based report without adding speculative impact.
Rank reconnaissance-derived attack surfaces and design evidence-driven tests without active exploitation.
Test ranked attack surfaces autonomously, preserve evidence, and turn new access into additional attack-chain hypotheses.
A compact routing skill for choosing vulnerability hypotheses; detailed payloads live in references, not here.
| name | js-analysis |
| description | Extract client-side attack surface from JS and sourcemaps without dictating the order of investigation. |
| metadata | {"tags":"js,spa,endpoint-extraction,sourcemap"} |
从前端代码里恢复真实业务接口、参数、认证入口、路由、状态管理和隐藏功能,为后续攻击面分析提供结构化材料。
_endpoint_params.json、_login_links.json、_secrets_found.jsonreferences/INDEX.md;候选资源:js-analysis-vulnforge.md、vue-spa-attacks.md