Skip to main content
تشغيل أي مهارة في Manus
بنقرة واحدة
مستودع GitHub

-communitytools-custom

يحتوي -communitytools-custom على 27 من skills المجمعة من LeoWSY-hashblue، مع تغطية مهنية على مستوى المستودع وصفحات skill داخل الموقع.

skills مجمعة
27
Stars
3
محدث
2026-05-26
Forks
1
التغطية المهنية
3 فئات مهنية · 100% مصنفة
مستكشف المستودعات

Skills في هذا المستودع

authentication
محللو أمن المعلومات

Authentication security testing - auth bypass, JWT attacks, OAuth flaws, password attacks, 2FA bypass, CAPTCHA bypass, and bot detection evasion.

2026-05-26
evasion
محللو أمن المعلومات

AV/EDR evasion and detection bypass — AMSI, ETW, API unhooking, process injection, AppLocker bypass, LOLBins, shellcode obfuscation.

2026-05-26
exchange-sharepoint
محللو أمن المعلومات

Microsoft Exchange and SharePoint attack techniques — enumeration, ProxyLogon/ProxyShell/ProxyToken exploitation, mailbox access, SharePoint file exfiltration.

2026-05-26
system
محللو أمن المعلومات

System exploitation testing - Active Directory attacks, privilege escalation (Linux/Windows), and exploit development.

2026-05-26
tunneling
مطوّرو البرمجيات

Internal network pivoting and traffic tunneling — FRP, Chisel, Ligolo-ng, SSH, ReGeorg, DNS tunneling, EarthWorm, Ngrok.

2026-05-26
ai-threat-testing
محللو أمن المعلومات

Offensive AI security testing and exploitation framework. Systematically tests LLM applications for OWASP Top 10 vulnerabilities including prompt injection, model extraction, data poisoning, and supply chain attacks. Integrates with pentest workflows to discover and exploit AI-specific threats.

2026-05-11
api-security
محللو أمن المعلومات

API security testing - GraphQL, REST API, WebSocket, and Web-LLM attack techniques.

2026-05-11
cloud-containers
محللو أمن المعلومات

Cloud and container security testing - AWS, Azure, GCP, Docker, and Kubernetes misconfigurations and exploitation.

2026-05-11
coordination
محللو أمن المعلومات

Pentest coordination — orchestrates executor and validator agents with context-controlled spawning. Entry point for all engagements.

2026-05-11
cryptography
محللو أمن المعلومات

Cryptanalysis techniques — lattice attacks, padding oracles, weak-RNG exploitation, signature forgery, secret-sharing recovery.

2026-05-11
dfir
محللو أمن المعلومات

Digital forensics and incident response - Windows event log analysis, PCAP forensics, filesystem artifact analysis, AD attack detection, and timeline correlation. Use when investigating security incidents, analyzing Sherlocks, or performing threat hunting on provided evidence files.

2026-05-11
essential-tools
محللو أمن المعلومات

Core pentesting tools and methodology - Burp Suite usage, Playwright automation, binary analysis, testing methodology, and professional reporting standards.

2026-05-11
hackerone
محللو أمن المعلومات

HackerOne bug bounty automation - parses scope CSVs, deploys parallel pentesting agents per asset, validates PoCs, and generates platform-ready submission reports.

2026-05-11
hackthebox
محللو أمن المعلومات

HackTheBox platform operations and automations to solve challenges, machines and capture the flags hacking competitions

2026-05-11
infrastructure
محللو أمن المعلومات

Network infrastructure testing - port scanning, DNS attacks, MITM, VLAN hopping, IPv6, SMB/NetBIOS, sniffing, and DoS assessment.

2026-05-11
injection
محللو أمن المعلومات

Injection vulnerability testing - SQL, NoSQL, OS Command, SSTI, XXE, and LDAP/XPath injection techniques.

2026-05-11
mobile-security
محللو أمن المعلومات

Mobile application security testing — Android (smali, Frida, IL2CPP, Flutter AOT, root detection), iOS (jailbreak, Objection).

2026-05-11
reconnaissance
محللو أمن المعلومات

Domain assessment and web application mapping - subdomain discovery, port scanning, endpoint enumeration, API discovery, and attack surface analysis.

2026-05-11
reverse-engineering
محللو أمن المعلومات

Static and dynamic reverse engineering — ELF/PE analysis, custom-VM bytecode, packed binaries, anti-debug bypass, Frida hooking.

2026-05-11
server-side
محللو أمن المعلومات

Server-side vulnerability testing - SSRF, HTTP Request Smuggling, Path Traversal, File Upload, Insecure Deserialization, and Host Header injection.

2026-05-11
skill-prune
محللو أمن المعلومات

Identify and remove negative-ROI skill content — orphan files, never-read entries, duplicates, content reintroducing challenge-specific lore. Inverse of /skill-update. Use during quarterly maintenance or after the linter flags issues.

2026-05-11
skill-update
مطوّرو البرمجيات

Skill creation, update and management — generates skill directory structure, validates against best practices, enforces line count limits. Use when creating, updating, or improving skills.

2026-05-11
source-code-scanning
محللو أمن المعلومات

Security-focused source code review and SAST. Scans for vulnerabilities (OWASP Top 10, CWE Top 25), CVEs in third-party dependencies/packages, hardcoded secrets, malicious code, and insecure patterns. Use when given source code, a repo path, or asked to "audit", "scan", "review" code security, or "check dependencies for CVEs".

2026-05-11
web-app-logic
محللو أمن المعلومات

Web application logic testing - business logic flaws, race conditions, access control, cache poisoning/deception, and information disclosure.

2026-05-11
transilience-report-style
المصممون الجرافيكيون

Threat Intelligence Report Design System — ReportLab-based PDF generation for A4 reports with Transilience branding, typography, and layout standards.

2026-04-09
cve-risk-score
محللو أمن المعلومات

Retrieve CVE risk scores from NVD. Auto-invoked whenever a CVE ID is mentioned to display CVSS score, severity, CWE, and description.

2026-04-09
patt-fetcher
محللو أمن المعلومات

Fetches and extracts payloads from PayloadsAllTheThings on demand. Bake into executor prompts for live payload enrichment.

2026-04-09