Skip to main content

Skills في هذا المستودع

tomysh1337/openstarry-code - الصفحة ١٠

جمع SkillsMP عدد ٤٨٤ من skills من tomysh1337/openstarry-code. افتح أي skill لمراجعة مصدره وتفاصيله.

tomysh1337/openstarry-code

عرض ٤٠ من أصل ٤٨٤ skills مجمعة.

المهنة
غير مصنف
الوصف

Reverse and assess Android and iOS applications with Frida, Objection, runtime instrumentation, pinning bypass, and OWASP MASTG workflows.

لغة النص الأصلي: الصينية

آخر تحديث
المهنة
غير مصنف
الوصف

主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。

لغة النص الأصلي: الصينية

آخر تحديث
المهنة
غير مصنف
الوصف

实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR…

لغة النص الأصلي: الصينية

آخر تحديث
المهنة
غير مصنف
الوصف

Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it…

لغة النص الأصلي: الصينية

آخر تحديث
المهنة
غير مصنف
الوصف

Reverse JavaScript-based custom DSL virtual machines, opcode dispatchers, constant tables, interpreter loops, and nonstandard WASM-like runtimes.

لغة النص الأصلي: الصينية

آخر تحديث
المهنة
غير مصنف
الوصف

Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, malware-like…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Master router for reverse engineering, authorized security research, CTF, binary, APK, JavaScript, firmware, mobile, malware, pwn, and API tasks. Use to select this package's specialized workflow and shared toolchain.

لغة النص الأصلي: الصينية

آخر تحديث
المهنة
غير مصنف
الوصف

Assess software supply chains, dependencies, SBOMs, CI/CD pipelines, container images, build provenance, signatures, and artifact integrity.

لغة النص الأصلي: الصينية

آخر تحديث
المهنة
غير مصنف
الوصف

Set up and gate Rust supply-chain audits with cargo-vet: supply-chain/ config.toml and audits.toml, exemptions, peer audit imports, certify criteria (safe-to-run / safe-to-deploy), inspect/diff workflow, and CI fail-closed checks for owned Cargo workspaces.…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Apply rustfmt, Clippy, Rust API Guidelines (high level), rustdoc, and idiomatic error and naming style when writing or reviewing Rust code. Use when Rust style, clippy, rustfmt, rustdoc, API guidelines, or Cargo workspace formatting and lints are in scope.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Decide when Rust `unsafe` is justified, document soundness invariants, minimize unsafe surface, and verify with Miri and review checklists. Use when writing, reviewing, or refactoring `unsafe` blocks, raw pointers, FFI, transmute, interior mutability that…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

SameSite cookie attribute pitfalls for Lax, Strict, and None; browser defaults, top-level navigation exceptions, cross-site POST gaps, and CSRF interactions. Use when session cookies lack or mis-set SameSite, CSRF defenses depend only on browser cookie…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Authorized review of SAML 2.0 assertion encryption: EncryptedAssertion, key transport, SP encryption-certificate management, and decrypt-before- signature-verify order pitfalls. Use when EncryptedAssertion, EncryptedKey, WantAssertionsEncrypted, or SP…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

SAML 2.0 metadata trust and hygiene for owned or authorized SP/IdP integrations: EntityID pinning, signing-certificate import, ACS/SSO endpoint allowlists, metadata URL fetch controls, expiry/rotation, and admin dual control. Use when reviewing federation…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

SAML 2.0 NameID format pitfalls for authorized SP/IdP review: email vs persistent vs transient identity keys, Format attribute mismatch, mutable subject linking, SPNameQualifier confusion, and account-merge ATO paths. Use when SAML Subject/NameID,…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Authorized lab methodology for SAML XML signature wrapping (XSW) awareness: verify-vs-parse node mismatch, duplicated assertions, and SP acceptance of unsigned identity. Use when SAMLResponse XML is in scope and signature wrapping, XSW, or “signed node ≠ used…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

High-level authorized assessment of SAML SSO misconfigurations: signature validation, assertion/response signing, audience restriction, ACS URL handling, and related SP/IdP trust issues. Use when enterprise SAML login, Assertion Consumer Service, or…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

When and how to run Static Application Security Testing (SAST) and Dynamic Application Security Testing (DAST), configure sensible baselines, and triage scanner noise into actionable work. Use when SAST, DAST, 静态扫描, 动态扫描, CodeQL, Semgrep, ZAP, Burp scan,…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Generate and review Software Bills of Materials (SBOM), map direct and transitive dependencies, and harden software supply-chain hygiene across package managers, CI builds, and container images. Use when producing CycloneDX or SPDX SBOMs, reviewing…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Enforce Software Bill of Materials (SBOM) generation in CI: CycloneDX and/or SPDX artifacts, build-linked attestation, publish-with-release, and hard gates when an SBOM is missing or empty. Use when wiring SBOM jobs in GitHub Actions, GitLab CI, or similar;…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Select the most specific installed skill for scientific computing, statistics, data science, machine learning, experiments, visualization, bioinformatics, chemistry, and research methods. Use for science, statistics, pandas, NumPy, SciPy, scikit-learn,…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Create and audit truthful, accessible, publication-ready scientific figures with Matplotlib, Seaborn, or Plotly. Use for figure design, multi-panel layouts, uncertainty and missing-data displays, color/contrast review, image metadata validation, and journal…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Draft, revise, and audit scientific manuscripts or reports with explicit evidence provenance, reporting-guideline coverage, authorship accountability, confidentiality controls, and local consistency checks. Use for manuscript sections, references,…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Authorized assessment and hardening of SCIM 2.0 user/group provisioning: token auth, endpoint exposure, filter/PATCH abuse, privilege via attributes, deprovisioning gaps, and cross-tenant isolation. Use when SCIM, /Users, /Groups, ServiceProviderConfig, bulk…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Bitnami SealedSecrets and kubeseal for GitOps-friendly secrets on owned clusters: seal plaintext Secrets into SealedSecret CRs, choose scope (strict/namespace-wide/ cluster-wide), manage controller keys and rotation, and avoid decrypt-side misuse. Use when…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

CI/CD secrets hygiene: prefer OIDC and short-lived federated cloud roles over long-lived tokens, scope secrets by environment, block fork-PR access, and keep credentials out of logs and artifacts. Use when GitHub Actions/GitLab OIDC, static AWS/GCP/Azure keys…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Secrets management hygiene for org-owned code and platforms: keep secrets out of source, use vault/platform secret stores, least-privilege injection, rotation and revocation, and safe logging. Use when secrets management, 密钥管理, .env secrets, API keys in repo,…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Phase-by-phase secure software development lifecycle (SSDLC) checklist for org-owned products: requirements, design, implementation, verification, release, and operations. Use when secure SDLC, 安全开发生命周期, SSDLC, security release gate, security requirements, or…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Design and run an organizational security champion program: role definitions, selection, training paths, office hours, metrics, and escalation between product teams and AppSec. Use when security champions, AppSec champions, federated security program,…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Select the most specific installed skill for security research, CTF, vulnerability analysis, authentication, reverse engineering, malware, mobile, binary, crypto, and forensics. Use for security, CTF, pentest, APK, Ghidra, IDA, Frida, pwn, PCAP, malware, 安全,…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Isolated analysis environment management for malware and exploit testing. Create and manage isolated VMs, configure Cuckoo Sandbox, set up REMnux/FlareVM environments, manage Docker-based analysis containers, and capture filesystem and process changes.

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Render a single 3-15s video clip via Seedance 2.0. Supports two backends: OpenRouter (default, model bytedance/seedance-2.0) and the official Volcengine ARK / BytePlus ModelArk endpoint (model doubao-seedance-2-0-260128 / dreamina-seedance-2-0-260128).…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Author, test, and tune Semgrep rules for org-owned codebases: YAML rule schema, pattern/pattern-either/pattern-not, metavariables, taint mode, message/severity/metadata, language packs, and rule tests. Use when writing custom Semgrep rules, fixing false…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

When the user wants to audit, review, or diagnose SEO issues on their site. Also use when the user mentions "SEO audit," "technical SEO," "why am I not ranking," "SEO issues," "on-page SEO," "meta tags review," "SEO health check," "my traffic dropped," "lost…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Plan and execute progressive service-mesh mTLS rollouts on owned clusters: baseline inventory, PERMISSIVE then STRICT, canary namespaces, DestinationRule / peer policy alignment, plaintext exception budgets, and evidence-based cutover. Use when enabling mesh…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Service Worker security: scope, registration source, fetch hijacking, cache isolation, updates, push/notifications, and CSP interaction. Use when adding or reviewing service workers, Workbox, PWA offline shells, or SW fetch interception. Authorized…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Defend against session cookie theft with secure cookie flags, session binding, rotation and invalidation, short lifetimes, and theft-window reduction. Use when hardening cookie-based sessions, designing session middleware, responding to XSS or network theft…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Detect and prevent session fixation: pre-auth session IDs that remain valid after login, URL/cookie injection of attacker-chosen SIDs, and missing regenerate-on-auth. Use when assessing cookie, header, or URL-based session mechanisms under authorization and…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Design idle and absolute session timeouts, sliding renewal, server-side TTL, and re-auth UX. Use when choosing session lifetime, idle vs absolute expiry, sliding windows, remember-me bounds, or timeout middleware for cookie or server sessions under clear…

لغة النص الأصلي: الإنجليزية

آخر تحديث
المهنة
غير مصنف
الوصف

Manages shadcn components and projects — adding, searching, fixing, debugging, styling, and composing UI, including chat interfaces. Provides project context, component docs, and usage examples. Applies when working with shadcn/ui, component registries,…

لغة النص الأصلي: الإنجليزية

آخر تحديث
عرض ٤٠ من أصل ٤٨٤ skills مجمعة.