Skip to main content
yhy0
ملف منشئ GitHub

yhy0

عرض على مستوى المستودعات لـ ٥٨ skills مجمعة عبر ٥ مستودعات GitHub.

skills مجمعة
٥٨
مستودعات
٥
محدث
٣ أغسطس ٢٠٢٦
مستكشف المستودعات

المستودعات و skills الممثلة

ghsa-skill-builder
محللو أمن المعلومات

Use when building or updating vulnerability pattern Skills from multiple sources: GitHub Security Advisories (GHSA), HackerOne Hacktivity, or NVD. Triggers on keywords: GHSA, CVE, vulnerability skill, vuln pattern, update skills, security advisory, HackerOne,…

١٤ مارس ٢٠٢٦
ghsa-skill-builder
محللو أمن المعلومات

Use when building or updating vulnerability pattern Skills from multiple sources: GitHub Security Advisories (GHSA), HackerOne Hacktivity, or NVD. Triggers on keywords: GHSA, CVE, vulnerability skill, vuln pattern, update skills, security advisory, HackerOne,…

١٤ مارس ٢٠٢٦
go-vuln-auth-bypass
محللو أمن المعلومات

Use when auditing Go code involving authentication flows, RBAC policies, Kubernetes admission webhooks, JWT/OAuth token validation, or privilege escalation in cloud-native infrastructure. Covers CWE-287/863/269/284/285/862. Keywords: authentication bypass,…

١٤ مارس ٢٠٢٦
go-vuln-crypto-tls
محللو أمن المعلومات

Use when auditing Go code involving TLS configuration, certificate validation, JWT token parsing, SAML assertion verification, webhook signature checking, or cryptographic operations. Covers CWE-295/347/345. Keywords: InsecureSkipVerify, TLS, mTLS,…

١٤ مارس ٢٠٢٦
go-vuln-dos
محللو أمن المعلومات

Use when auditing Go code involving goroutine management, channel operations, HTTP request handling, resource allocation, or panic recovery. Covers CWE-400/770/476. Keywords: denial of service, goroutine leak, channel deadlock, panic recover, io.ReadAll,…

١٤ مارس ٢٠٢٦
go-vuln-info-disclosure
محللو أمن المعلومات

Use when auditing Go code involving logging, error handling, HTTP response data, Kubernetes Secret management, or credential storage. Covers CWE-200/532/522/312/552. Keywords: information disclosure, credential leak, log exposure, Kubernetes Secret, json tag,…

١٤ مارس ٢٠٢٦
go-vuln-injection
مطوّرو البرمجيات

Use when auditing Go code involving OS command execution, SQL queries, template rendering, or child command invocation. Covers CWE-78/89/77/94/88. Keywords: command injection, SQL injection, exec.Command, os/exec, database/sql, text/template, html/template,…

١٤ مارس ٢٠٢٦
go-vuln-path-traversal
مطوّرو البرمجيات

Use when auditing Go code involving file path operations, archive extraction, symlink handling, container volume mounts, or HTTP file serving. Covers CWE-22/59. Keywords: path traversal, directory traversal, filepath.Join, symlink, archive extraction, zip…

١٤ مارس ٢٠٢٦
عرض 8 من أصل ٢٨ skills مجمعة.
ai-security
محللو أمن المعلومات

Use when facing AI security challenges involving prompt injection, LLM jailbreaks, or AI agent exploitation

٢٥ أبريل ٢٠٢٦
binary
محللو أمن المعلومات

Use when facing binary exploitation (PWN) or reverse engineering challenges involving memory corruption, ROP chains, shellcode, binary analysis, decompilation, unpacking, or dynamic tracing

٢٥ أبريل ٢٠٢٦
cryptography
محللو أمن المعلومات

Use when facing cryptography challenges involving cipher analysis, key recovery, mathematical attacks, or protocol weaknesses

٢٥ أبريل ٢٠٢٦
file-transfer
مديرو الشبكات وأنظمة الحاسوب

Use when transferring files between remote environments and local Docker containers via litterbox.catbox.moe relay or base64 chunked fallback

٢٥ أبريل ٢٠٢٦
forensics-misc
مطوّرو البرمجيات

Use when facing digital forensics or misc challenges involving disk images, memory dumps, network captures, steganography, file format analysis, encoding puzzles, sandbox escapes, or archive manipulation

٢٥ أبريل ٢٠٢٦
infra-exploit
محللو أمن المعلومات

Use when conducting penetration testing, post-exploitation, lateral movement, domain attacks, cloud exploitation (AWS/GCP/Azure), container escape, or Kubernetes cluster attacks

٢٥ أبريل ٢٠٢٦
stagnation-recovery
المهن الحاسوبية الأخرى

Use when stuck, looping on same approach, making no progress after multiple tool calls, or receiving a stagnation warning from the system. Also trigger when you catch yourself retrying the same command with minor variations, getting repeated Permission denied…

٢٥ أبريل ٢٠٢٦
web-security
محللو أمن المعلومات

Use when facing web security challenges involving injection, authentication bypass, IDOR, access control, CSRF, HRS, server-side vulnerabilities, or web application exploitation

٢٥ أبريل ٢٠٢٦
عرض 8 من أصل ٢١ skills مجمعة.
sec-mentor-core
معلمو التعليم العالي، جميع الآخرون

Orchestrates SecMentor cybersecurity tutoring: routing, progress 1.1 protocol, evidence rules, P0 gate. Use when starting SecMentor, 学网络安全, or continuing learner/progress.json.

٣ أغسطس ٢٠٢٦
sec-mentor-review
معلمو التعليم العالي، جميع الآخرون

Writes SecMentor daily/weekly reviews to journal and events jsonl; updates still_fuzzy and recent_events without bloating progress.json. Use on 小结/复盘.

٣ أغسطس ٢٠٢٦
sec-mentor-stages
معلمو التعليم العالي، جميع الآخرون

Delivers SecMentor lessons with dynamic labs, structured evidence, mastery levels, and remediation from curriculum.yaml. Use after P0/placement when continuing study, 做实验, 验收, or 下一章.

٢٣ يوليو ٢٠٢٦
sec-mentor-ui
معلمو التعليم العالي، جميع الآخرون

SecMentor HTML for progress cards (Kami) and celebration pages with fireworks when points/milestones unlock. Quizzes stay chat-first. Use for 进度, 积分板, 烟花庆祝, 里程碑.

٢٣ يوليو ٢٠٢٦
sec-mentor-placement
معلمو التعليم العالي، جميع الآخرون

Runs SecMentor placement via chat-first interview and dynamic quizzes; sets recommended_start_after_p0 while keeping current_stage at P0. Use on 摸底/重测 or placement.status not done.

٢٠ يوليو ٢٠٢٦
sec-mentor-toolkit
معلمو التعليم العالي، جميع الآخرون

Guides Yakit/Burp and dynamic lab environments for SecMentor. Labs folder is optional examples; no pinned images or topic hard-binds. Use for 环境/代理/Docker/靶场.

٢٠ يوليو ٢٠٢٦
عرض ٥ من أصل ٥ مستودعات
تم تحميل كل المستودعات