Skip to main content

OpenAisec/Miko

SkillsMP has collected 49 skills from OpenAisec/Miko. Open a skill to review its source and details.

Latest recorded source activity
SkillsMP catalog refreshed
skills collected
49
GitHub stars
541
GitHub forks
27

Showing 40 of 49 collected skills.

occupation
Information Security Analysts
description

渗透测试实战技能 v1.2.0。覆盖信息收集、漏洞发现 (3梯队9+3+6类)、漏洞利用、后渗透、免杀全流程。 当用户给出具体目标 (IP/域名/URL) 且意图是攻击/利用/拿权限时触发。 不触发: 概念讨论、蓝队防御、代码审计、CVE文档查询。

Source text: Chinese

updated
occupation
Software Developers
description

所有联网操作必须通过此 skill 处理,包括:搜索、网页抓取、登录后操作、网络交互等。 触发场景:用户要求搜索信息、查看网页内容、访问需要登录的网站、操作网页界面、抓取社交媒体内容(小红书、微博、推特等)、读取动态渲染页面、以及任何需要真实浏览器环境的网络任务。

Source text: Chinese

updated
occupation
Software Developers
description

Direct browser control via CDP for web interaction: automation, scraping, testing, screenshots, and site/app work.

updated
occupation
Software Developers
description

Documentation reference for using Browser Use Cloud — the hosted API and SDK for browser automation. Use this skill whenever the user needs help with the Cloud REST API (v2 or v3), browser-use-sdk (Python or TypeScript), X-Browser-Use-API-Key authentication,…

updated
occupation
Software Developers
description

Documentation reference for writing Python code using the browser-use open-source library. Use this skill whenever the user needs help with Agent, Browser, or Tools configuration, is writing code that imports from browser_use, asks about @sandbox deployment,…

updated
occupation
Software Quality Assurance Analysts & Testers
description

QA-test a website or web app and return a 1-5 quality score (5 = flawless, 1 = broken) with evidence. Use when the user wants to test, QA, evaluate, score, or "check how good" a site, page, flow, or app — including a local dev server (e.g. "qa test…

updated
occupation
Software Developers
description

Controls a local browser from a sandboxed remote machine. Use when the agent is running in a sandbox (no GUI) and needs to navigate websites, interact with web pages, fill forms, take screenshots, or expose local dev servers via tunnels.

updated
occupation
Software Developers
description

Set up Browser Use Cloud payments with x402 — pay per request from a crypto wallet (USDC on Base mainnet), no signup or API key. Two setups it works out up front — "just use it" (set up a wallet so you or Claude Code can run cloud browser tasks paid from the…

updated
occupation
Information Security Analysts
description

Security audit workflow for authorized Java, .NET, PHP source and deployment artifact review.

Source text: Chinese

updated
occupation
Information Security Analysts
description

Professional code security audit skill covering 55+ vulnerability types. Enhanced with WooYun 88,636 real-world vulnerability cases (2010-2016). This skill should be used when performing security audits, vulnerability scanning, penetration testing…

Source text: Mixed languages

updated
occupation
Software Quality Assurance Analysts & Testers
description

Comprehensive code review guidance across frontend, backend, systems, architecture, quality, performance, and security.

updated
occupation
Information Security Analysts
description

Provides AI and machine learning techniques for CTF challenges. Use when attacking ML models, crafting adversarial examples, performing model extraction, prompt injection, membership inference, training data poisoning, fine-tuning manipulation, neural network…

updated
occupation
Software Developers
description

Provides cryptography attack techniques for CTF challenges. Use when attacking encryption, hashing, signatures, ZKP, PRNG, or mathematical crypto problems involving RSA, AES, ECC, lattices, LWE, CVP, number theory, Coppersmith, Pollard, Wiener, padding…

updated
occupation
Software Developers
description

Provides digital forensics and signal analysis techniques for CTF challenges. Use when analyzing disk images, memory dumps, event logs, network captures, cryptocurrency transactions, steganography, PDF analysis, Windows registry, Volatility, PCAP, Docker…

updated
occupation
Software Developers
description

Provides malware analysis and network traffic techniques for CTF challenges. Use when analyzing obfuscated scripts, malicious packages, custom crypto protocols, C2 traffic, PE/.NET binaries, RC4/AES encrypted communications, YARA rules, shellcode analysis,…

updated
occupation
Software Developers
description

Provides miscellaneous CTF challenge techniques for problems that do not cleanly fit the main categories. Use for encoding puzzles, pyjails, bash jails, RF/SDR, DNS oddities, unicode tricks, esoteric languages, QR or audio puzzles, constraint solving, game…

updated
occupation
Software Developers
description

Provides open source intelligence techniques for CTF challenges. Use when gathering information from public sources, social media, geolocation, DNS records, username enumeration, reverse image search, Google dorking, Wayback Machine, Tor relays, FEC filings,…

updated
occupation
Software Developers
description

Provides binary exploitation techniques for CTF challenges. Use when you already have a vulnerable native target or service and need to turn memory corruption or low-level primitives into code execution or privilege escalation, such as buffer overflows,…

updated
occupation
Software Developers
description

Provides reverse engineering techniques for CTF challenges. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode,…

updated
occupation
Software Developers
description

Provides web exploitation techniques for CTF challenges. Use when the target is primarily an HTTP application, API, browser client, template engine, identity flow, or smart-contract frontend/backend surface, including XSS, SQLi, SSTI, SSRF, XXE, JWT, auth…

updated
occupation
Software Developers
description

Generates a single standardized submission-style CTF writeup for competition handoff and organizer review. Use after solving a CTF challenge to document the solution steps, tools used, and lessons learned in a structured format.

updated
occupation
Software Developers
description

Authorized game security, reverse engineering, protocol analysis, memory analysis, hook, and automation workflow guide.

Source text: Chinese

updated
occupation
Software Developers
description

LibTV official CLI operation guide for managing LibTV canvas projects, nodes, groups, models, assets, and command-line workflows.

Source text: Chinese

updated
occupation
Software Developers
description

Generate medical device cybersecurity registration deliverables from project input files. Use when Codex needs to read DOCX/PDF/PNG project evidence such as user manuals, SRS, design documents, architecture diagrams, FDA cybersecurity guidance, or prior…

updated
occupation
Software Developers
description

Reverse engineering workflow for web, desktop binaries, mobile apps, network protocols, encryption, signatures, and dynamic analysis.

Source text: Chinese

updated
occupation
Software Developers
description

Solves CTF challenges by performing first-pass triage, identifying the dominant category, and routing execution to the right specialized ctf-* skill. Use when the user gives you a challenge bundle, a remote service, a suspicious file, or only a vague…

updated
occupation
Software Developers
description

Threat model, security audit, find vulnerabilities, check security of my app, risk assessment, penetration test prep, analyze attack surface, what could an attacker exploit. Use this skill whenever a user wants holistic security analysis of a codebase,…

updated
occupation
Information Security Analysts
description

Go语言免杀技术套件,结合SGN预处理、多层加密、IPv4/UUID/MAC/IPv6混淆、VEH内存保护、NTDLL脱钩、冷门回调执行、抗沙箱检测、减熵处理、静态伪装、版本信息嵌入等技术生成高免杀Loader

Source text: Chinese

updated
occupation
Information Security Analysts
description

API发现与未授权测试入口 - 主动探测各类API端点,对发现的API进行未授权访问测试

Source text: Chinese

updated
occupation
Information Security Analysts
description

JS信息收集入口 - 提取硬编码凭据、API路径、路由、认证逻辑、运行时存储;检测到框架特征时触发对应子技能

Source text: Chinese

updated
occupation
Information Security Analysts
description

登录与鉴权测试 - Token权限分析、认证绕过、暴力破解、JWT/OAuth攻击、验证码绕过

Source text: Chinese

updated
occupation
Information Security Analysts
description

单网站渗透主入口 - 流程编排,按阶段触发各子技能

Source text: Chinese

updated
occupation
Information Security Analysts
description

信息收集入口 - 目标类型判断、CDN检测、WAF识别、端口扫描

Source text: Chinese

updated
occupation
Information Security Analysts
description

渗透测试禁止项 - 集中管理所有禁止测试的端点、操作和范围限制

Source text: Chinese

updated
occupation
Information Security Analysts
description

工具路径与配置 - 集中管理所有工具路径、配套文件、MCP工具、字典

Source text: Chinese

updated
occupation
Information Security Analysts
description

漏洞发现与验证 - 根据前期发现的功能点,针对性测试各类Web漏洞

Source text: Chinese

updated
occupation
Information Security Analysts
description

Dump DEX files from a running Android app for unpacking/deobfuscation. Activate when the user wants to unpack an Android APK, dump DEX from memory, extract decrypted DEX files, or defeat class-loading packing.

updated
occupation
Information Security Analysts
description

Generate Frida hook scripts using modern Frida API. Activate when the user wants to write Frida scripts, hook functions at runtime, trace calls or arguments or return values, intercept native or ObjC or Java methods, dump memory or exports, or handle native…

updated
occupation
Software Developers
description

IDAPython and IDALib script reference for reverse engineering. Activate when the user needs to write IDAPython scripts in IDA, use IDALib for headless analysis, operate on IDB databases, debug with IDA, manipulate memory/registers, traverse…

updated
occupation
Software Developers
description

Dump decrypted iOS app binaries (砸壳) from jailbroken devices using frida-ios-dump. Activate when the user wants to decrypt an iOS app, dump an IPA from a device, or extract a decrypted Mach-O binary for reverse engineering.

updated
Showing 40 of 49 collected skills.