Skip to main content
yhy0
Profil créateur GitHub

yhy0

Vue par dépôt de 58 skills collectés dans 5 dépôts GitHub.

skills collectés
58
dépôts
5
mis à jour
3 août 2026
explorateur de dépôts

Dépôts et skills représentatifs

ghsa-skill-builder
Analystes en sécurité de l'information

Use when building or updating vulnerability pattern Skills from multiple sources: GitHub Security Advisories (GHSA), HackerOne Hacktivity, or NVD. Triggers on keywords: GHSA, CVE, vulnerability skill, vuln pattern, update skills, security advisory, HackerOne,…

14 mars 2026
ghsa-skill-builder
Analystes en sécurité de l'information

Use when building or updating vulnerability pattern Skills from multiple sources: GitHub Security Advisories (GHSA), HackerOne Hacktivity, or NVD. Triggers on keywords: GHSA, CVE, vulnerability skill, vuln pattern, update skills, security advisory, HackerOne,…

14 mars 2026
go-vuln-auth-bypass
Analystes en sécurité de l'information

Use when auditing Go code involving authentication flows, RBAC policies, Kubernetes admission webhooks, JWT/OAuth token validation, or privilege escalation in cloud-native infrastructure. Covers CWE-287/863/269/284/285/862. Keywords: authentication bypass,…

14 mars 2026
go-vuln-crypto-tls
Analystes en sécurité de l'information

Use when auditing Go code involving TLS configuration, certificate validation, JWT token parsing, SAML assertion verification, webhook signature checking, or cryptographic operations. Covers CWE-295/347/345. Keywords: InsecureSkipVerify, TLS, mTLS,…

14 mars 2026
go-vuln-dos
Analystes en sécurité de l'information

Use when auditing Go code involving goroutine management, channel operations, HTTP request handling, resource allocation, or panic recovery. Covers CWE-400/770/476. Keywords: denial of service, goroutine leak, channel deadlock, panic recover, io.ReadAll,…

14 mars 2026
go-vuln-info-disclosure
Analystes en sécurité de l'information

Use when auditing Go code involving logging, error handling, HTTP response data, Kubernetes Secret management, or credential storage. Covers CWE-200/532/522/312/552. Keywords: information disclosure, credential leak, log exposure, Kubernetes Secret, json tag,…

14 mars 2026
go-vuln-injection
Développeurs de logiciels

Use when auditing Go code involving OS command execution, SQL queries, template rendering, or child command invocation. Covers CWE-78/89/77/94/88. Keywords: command injection, SQL injection, exec.Command, os/exec, database/sql, text/template, html/template,…

14 mars 2026
go-vuln-path-traversal
Développeurs de logiciels

Use when auditing Go code involving file path operations, archive extraction, symlink handling, container volume mounts, or HTTP file serving. Covers CWE-22/59. Keywords: path traversal, directory traversal, filepath.Join, symlink, archive extraction, zip…

14 mars 2026
Affichage de 8 skills collectés sur 28.
ai-security
Analystes en sécurité de l'information

Use when facing AI security challenges involving prompt injection, LLM jailbreaks, or AI agent exploitation

25 avr. 2026
binary
Analystes en sécurité de l'information

Use when facing binary exploitation (PWN) or reverse engineering challenges involving memory corruption, ROP chains, shellcode, binary analysis, decompilation, unpacking, or dynamic tracing

25 avr. 2026
cryptography
Analystes en sécurité de l'information

Use when facing cryptography challenges involving cipher analysis, key recovery, mathematical attacks, or protocol weaknesses

25 avr. 2026
file-transfer
Administrateurs de réseaux et de systèmes informatiques

Use when transferring files between remote environments and local Docker containers via litterbox.catbox.moe relay or base64 chunked fallback

25 avr. 2026
forensics-misc
Développeurs de logiciels

Use when facing digital forensics or misc challenges involving disk images, memory dumps, network captures, steganography, file format analysis, encoding puzzles, sandbox escapes, or archive manipulation

25 avr. 2026
infra-exploit
Analystes en sécurité de l'information

Use when conducting penetration testing, post-exploitation, lateral movement, domain attacks, cloud exploitation (AWS/GCP/Azure), container escape, or Kubernetes cluster attacks

25 avr. 2026
stagnation-recovery
Autres occupations informatiques

Use when stuck, looping on same approach, making no progress after multiple tool calls, or receiving a stagnation warning from the system. Also trigger when you catch yourself retrying the same command with minor variations, getting repeated Permission denied…

25 avr. 2026
web-security
Analystes en sécurité de l'information

Use when facing web security challenges involving injection, authentication bypass, IDOR, access control, CSRF, HRS, server-side vulnerabilities, or web application exploitation

25 avr. 2026
Affichage de 8 skills collectés sur 21.
5 dépôts affichés sur 5
Tous les dépôts sont affichés