Skip to main content
Ejecuta cualquier Skill en Manus
con un clic
$pwd:
yhy0
GitHub creator profile

yhy0

Repository-level view of 51 collected skills across 3 GitHub repositories, including approximate occupation coverage.

skills collected
51
repositories
3
occupation fields
1
updated
2026-04-25
occupation focus
Major fields detected across this creator.
repository explorer

Repositories and representative skills

#001
ghsa-skill-builder
28 skills7111updated 2026-03-14
55% of creator
ghsa-skill-builder
Analistas de seguridad de la información

Use when building or updating vulnerability pattern Skills from multiple sources: GitHub Security Advisories (GHSA), HackerOne Hacktivity, or NVD. Triggers on keywords: GHSA, CVE, vulnerability skill, vuln pattern, update skills, security advisory, HackerOne, H1, hacktivity, pentest skill, bug bounty, check for updates.

2026-03-14
ghsa-skill-builder
Analistas de seguridad de la información

Use when building or updating vulnerability pattern Skills from multiple sources: GitHub Security Advisories (GHSA), HackerOne Hacktivity, or NVD. Triggers on keywords: GHSA, CVE, vulnerability skill, vuln pattern, update skills, security advisory, HackerOne, H1, hacktivity, pentest skill, bug bounty, check for updates.

2026-03-14
go-vuln-auth-bypass
Analistas de seguridad de la información

Use when auditing Go code involving authentication flows, RBAC policies, Kubernetes admission webhooks, JWT/OAuth token validation, or privilege escalation in cloud-native infrastructure. Covers CWE-287/863/269/284/285/862. Keywords: authentication bypass, authorization bypass, RBAC, admission webhook, JWT, OAuth, privilege escalation, Rancher, Kyverno, impersonation, namespace isolation, middleware auth

2026-03-14
go-vuln-crypto-tls
Analistas de seguridad de la información

Use when auditing Go code involving TLS configuration, certificate validation, JWT token parsing, SAML assertion verification, webhook signature checking, or cryptographic operations. Covers CWE-295/347/345. Keywords: InsecureSkipVerify, TLS, mTLS, certificate validation, JWT algorithm, SAML signature, cosign, sigstore, hmac.Equal, X.509, webhook HMAC

2026-03-14
go-vuln-dos
Analistas de seguridad de la información

Use when auditing Go code involving goroutine management, channel operations, HTTP request handling, resource allocation, or panic recovery. Covers CWE-400/770/476. Keywords: denial of service, goroutine leak, channel deadlock, panic recover, io.ReadAll, resource exhaustion, OOM, HTTP/2 abuse, protobuf, unbounded allocation, rate limiting

2026-03-14
go-vuln-info-disclosure
Analistas de seguridad de la información

Use when auditing Go code involving logging, error handling, HTTP response data, Kubernetes Secret management, or credential storage. Covers CWE-200/532/522/312/552. Keywords: information disclosure, credential leak, log exposure, Kubernetes Secret, json tag, struct formatting, error message, stack trace, Rancher, Argo CD, sensitive data

2026-03-14
go-vuln-injection
Analistas de seguridad de la información

Use when auditing Go code involving OS command execution, SQL queries, template rendering, or child command invocation. Covers CWE-78/89/77/94/88. Keywords: command injection, SQL injection, exec.Command, os/exec, database/sql, text/template, html/template, argument injection, shell injection, Gogs, Grafana, MCP stdio

2026-03-14
go-vuln-path-traversal
Analistas de seguridad de la información

Use when auditing Go code involving file path operations, archive extraction, symlink handling, container volume mounts, or HTTP file serving. Covers CWE-22/59. Keywords: path traversal, directory traversal, filepath.Join, symlink, archive extraction, zip slip, tar, volume mount, go-git, Helm chart, os.Open, filepath.Clean

2026-03-14
Showing top 8 of 28 collected skills in this repository.
#002
CHYing-agent
21 skills49044updated 2026-04-25
41% of creator
ai-security
Analistas de seguridad de la información

Use when facing AI security challenges involving prompt injection, LLM jailbreaks, or AI agent exploitation

2026-04-25
binary
Analistas de seguridad de la información

Use when facing binary exploitation (PWN) or reverse engineering challenges involving memory corruption, ROP chains, shellcode, binary analysis, decompilation, unpacking, or dynamic tracing

2026-04-25
cryptography
Analistas de seguridad de la información

Use when facing cryptography challenges involving cipher analysis, key recovery, mathematical attacks, or protocol weaknesses

2026-04-25
file-transfer
Desarrolladores de software

Use when transferring files between remote environments and local Docker containers via litterbox.catbox.moe relay or base64 chunked fallback

2026-04-25
forensics-misc
Analistas de seguridad de la información

Use when facing digital forensics or misc challenges involving disk images, memory dumps, network captures, steganography, file format analysis, encoding puzzles, sandbox escapes, or archive manipulation

2026-04-25
infra-exploit
Analistas de seguridad de la información

Use when conducting penetration testing, post-exploitation, lateral movement, domain attacks, cloud exploitation (AWS/GCP/Azure), container escape, or Kubernetes cluster attacks

2026-04-25
stagnation-recovery
Desarrolladores de software

Use when stuck, looping on same approach, making no progress after multiple tool calls, or receiving a stagnation warning from the system. Also trigger when you catch yourself retrying the same command with minor variations, getting repeated Permission denied or timeout errors, or unable to advance past a specific step for 10+ tool calls.

2026-04-25
web-security
Analistas de seguridad de la información

Use when facing web security challenges involving injection, authentication bypass, IDOR, access control, CSRF, HRS, server-side vulnerabilities, or web application exploitation

2026-04-25
Showing top 8 of 21 collected skills in this repository.
#003
init-skills
2 skills131updated 2025-12-29
3.9% of creator
Mostrando 3 de 3 repositorios
Todos los repositorios cargados