Skip to main content
تشغيل أي مهارة في Manus
بنقرة واحدة

pwn-request

Use when hunting Pwn Request vulnerabilities where pull_request_target workflows checkout attacker-controlled PR code and execute it in a privileged context with access to repository secrets. Trigger on: "pwn request", "pull_request_target", "checkout PR head", "npm install in CI", "lifecycle scripts in CI", "preinstall script", "postinstall script", "package.json scripts CI", "npm ci ignore-scripts false", "actions/checkout ref pull request head sha", privileged workflow running PR code, "Gato-X", supply chain via PR lifecycle scripts.

النجوم٤
التفرعات١
آخر تحديث١٤ مارس ٢٠٢٦ في ١٣:١٧
SKILL.md
readonly