This skill should be used when working with Bun runtime, bun:sqlite, Bun.serve, bun:test, or when "Bun", "bun:test", or Bun-specific patterns are mentioned.
لغة النص الأصلي: الإنجليزية
القائمة
جمع SkillsMP عدد ٢٢ من skills من m-sec-org/BreachWeave. افتح أي skill لمراجعة مصدره وتفاصيله.
عرض ٢٢ من أصل ٢٢ skills مجمعة.
This skill should be used when working with Bun runtime, bun:sqlite, Bun.serve, bun:test, or when "Bun", "bun:test", or Bun-specific patterns are mentioned.
لغة النص الأصلي: الإنجليزية
pi-mono agent framework reference (github.com/badlogic/pi-mono). TRIGGER when: writing agent code using pi-ai/pi-agent-core/pi-coding-agent packages, defining tools with TypeBox schemas, implementing TUI or Web UI over an agent core, building extensions that…
لغة النص الأصلي: الإنجليزية
UI/UX design intelligence. 50 styles, 21 palettes, 50 font pairings, 20 charts, 8 stacks (React, Next.js, Vue, Svelte, SwiftUI, React Native, Flutter, Tailwind). Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance,…
لغة النص الأصلي: الإنجليزية
Active Directory 域渗透全链路指导技能。基于 GOAD (Game of Active Directory) 靶场实战经验, 涵盖从初始侦察、用户枚举、密码攻击、中继与投毒、ADCS证书攻击、MSSQL利用、提权、 横向移动、凭据提取、ACL滥用、委派攻击、域信任利用到域控拿下的完整渗透链。 当用户提到以下任何关键词时,务必触发此技能: AD渗透、域渗透、Active Directory、域控攻击、内网渗透、kerberoasting、AS-REP roasting、 NTLM…
لغة النص الأصلي: الصينية
Browser automation CLI for AI agents. Use when the user needs to interact with websites, including navigating pages, filling forms, clicking buttons, taking screenshots, extracting data, testing web apps, or automating any browser task. Triggers include…
لغة النص الأصلي: الإنجليزية
Help with ffuf-based Web parameter fuzzing. Use this skill whenever the user wants to fuzz Web request paths, query parameters, headers, POST bodies, JSON fields, or raw HTTP requests with ffuf, or when they ask for an ffuf command, wordlist choice,…
لغة النص الأصلي: الإنجليزية
Navigate the fuzzDicts repository and choose the right dictionary or payload list for authorized Web directory scanning, parameter fuzzing, upload bypass testing, subdomain enumeration, API discovery, credential spraying, and vuln-specific fuzzing. Use this…
لغة النص الأصلي: الإنجليزية
CTF/靶场多层内网渗透指导与自动化脚本生成技能。基于 NPS C2 通道,覆盖从初始侦察、网段发现、 服务利用、Windows/Linux 提权、凭据收集与复用、域渗透(ADCS/noPac/Zerologon)、 云原生/K8s/Docker 逃逸到横向移动的完整渗透链,目标是拿到 FLAG 或域控权限。 触发场景:用户提到内网渗透、CTF内网、靶场、多层内网、横向移动、提权、凭据获取、mimikatz、 hash传递、域渗透、域控攻击、云原生渗透、Docker逃逸、K8s渗透、fscan扫描、服务利用、…
لغة النص الأصلي: الصينية
JWT and OAuth token attack playbook. Use when validating token trust, signing algorithms, key handling, claim abuse, bearer flows, and OAuth account-binding weaknesses.
لغة النص الأصلي: الإنجليزية
Help with authorized JWT assessment using ticarpi/jwt_tool. Use this skill whenever the user mentions `jwt_tool`, wants commands for JWT decoding, verification, secret cracking, claim tampering, playbook scans, `alg:none`, key confusion, JWKS spoofing or…
لغة النص الأصلي: الإنجليزية
通用已知产品/框架漏洞利用专项技能。适用于 fscan/Nuclei/Wappalyzer 识别出目标运行已知产品(OA系统、CMS、中间件、框架)后的标准利用流程。 核心原则:已知产品必须 Nuclei 先行,不走盲测渗透。覆盖 Nuclei 精准扫描、模板分析、手工验证、环境诊断、命令执行方式选择、NPS 收口。 触发场景:fscan…
لغة النص الأصلي: الصينية
Help with safe, practical use of ProjectDiscovery Nuclei for authorized scanning. Use this skill whenever the user wants to run `nuclei`, choose templates, filter by tags or severity, scan one host or a target list, validate or run a custom template, tune…
لغة النص الأصلي: الإنجليزية
Payload crafting and bypass research for vulnerability verification
لغة النص الأصلي: الإنجليزية
Browse the bundled PayloadsAllTheThings corpus for CTF and web security payloads, bypasses, fuzz strings, exploit ideas, and methodology notes. Use when Agent needs to locate payloads by vulnerability category during CTFs, pentests, or challenge solving, then…
لغة النص الأصلي: الصينية
Help with authorized Web pentest, Web fuzzing, and CTF-style vulnerability analysis. Use this skill whenever the user wants payload ideas, fuzz dictionaries, quick probe strings, test methodology, response-difference heuristics, or per-vulnerability…
لغة النص الأصلي: الإنجليزية
安全构造 PHP payload 的专项技能。解决 bash/shell 转义导致 PHP 代码损坏的问题,提供经过验证的 payload 模板。 触发场景:用户需要通过 bash/shell 写入 PHP 文件(echo、printf、redis-cli -x、curl -d)、 遇到 $_POST/$_GET 变量被 bash 展开、PHP 代码写入后不执行、disable_functions bypass、 构造 webshell、构造诊断页、构造文件下载器、heredoc 写法、base64…
لغة النص الأصلي: الصينية
Fast reconnaissance - discover assets, entry points, attack surface, and hypotheses
لغة النص الأصلي: الصينية
Windows/Linux 场景下基于 Redis 未授权访问写入 Web 根并获取稳定命令执行、随后快速收敛到 NPS 的专项技能。只要用户提到 Redis、Redis未授权、6379、fscan 提示 unauthorized file、CONFIG SET dir/dbfilename、写 webshell、写计划任务、写 ssh key,或者已经确认 Redis 能写入 Web 目录,就应优先使用本技能,而不是走泛化 Web 利用或 SMB 分支。尤其在用户已经有上游跳板、NPS 通道、HTTP…
لغة النص الأصلي: الصينية
Windows/Linux 远程命令执行规范技能。覆盖 NPS execcmd 通用规范、Windows cmd /c 要求与绝对路径、 Linux nohup/后台执行、wmic/setsid 后台启动、工具上传语义、常用命令路径参考。 触发场景:用户通过 NPS execcmd 在受控主机上执行命令、遇到命令不回显、命令超时、 路径错误、找不到命令、工具上传后执行失败、后台进程启动、文件下载传输、 环境变量/PATH 异常时使用。同时适用于 Windows 和 Linux 主机。
لغة النص الأصلي: الصينية
SSRF playbook. Use when the server fetches URLs, resolves hostnames, imports remote content, or can be driven toward internal networks, cloud metadata, or secondary protocols.
لغة النص الأصلي: الإنجليزية
用于 pentest-agent 的 targeted-pentest 子 agent,在已锁定的 hypothesis_id、kind 与 entry_point 上执行单假设定向验证。适用于 Web、API、认证、浏览器端、服务端、Node.js 与 CVE 线索的验证场景;在同一假设内完成基线确认、payload 研究、最小化利用、证据收集、结论判定与 goal 提交。不用于宽泛 recon、不切换到其他假设、也不做与当前假设无关的发散测试。
لغة النص الأصلي: الصينية
Use this skill whenever the user wants to crawl a website with the `tch-headless` or `TCH-EZ-Headless` browser crawler for a quick headless pass, especially for dynamic pages, Chrome-based automation, request capture, sitemap-style output inspection, or…
لغة النص الأصلي: الإنجليزية