Skip to main content
تشغيل أي مهارة في Manus
بنقرة واحدة

clickjacking-hunter

النجوم١٥
التفرعات٧
آخر تحديث٢٨ يونيو ٢٠٢٦ في ١٦:٤٦

Tests sensitive state-changing pages for clickjacking / UI-redress weaknesses by auditing frame-protection headers, cookie attributes, and pre-fillable URL parameters. Use when a web app has destructive or account-modifying actions (password change, transfer, delete) that complete with a single click; when X-Frame-Options / CSP frame-ancestors are missing or permissive; or when the orchestrator needs to confirm whether a finding can be exploited without a secondary confirmation. Produces findings with CWE-1021 mapping, a local framing PoC, and developer-facing header/cookie remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml.

التثبيت

التثبيت باستخدام Codex أو Claude انسخ هذا Prompt والصقه في Codex أو Claude أو مساعد آخر ليراجع صفحة Skill ويثبّتها لك.

مستكشف الملفات
2 ملفات
SKILL.md
readonly