Skip to main content
Manusで任意のスキルを実行
ワンクリックで
GitHub リポジトリ

RedteamAgent

RedteamAgent には NeoTheCapt から収集した 31 個の skills があり、リポジトリ単位の職業カバレッジとサイト内 skill 詳細ページを表示します。

収集済み skills
31
Stars
94
更新
2026-05-02
Forks
21
職業カバレッジ
2 件の職業カテゴリ · 100% 分類済み
リポジトリエクスプローラー

このリポジトリの skills

business-logic-testing
ソフトウェア開発者

Business logic vulnerability detection — workflow bypass, price manipulation, state abuse, and application-specific flaws

2026-05-02
sensitive-data-detection
情報セキュリティアナリスト

Detect PII, credentials, and corporate sensitive data in API responses, source code, files, headers, and database extracts

2026-05-02
sqli-testing
ソフトウェア開発者

Detect and exploit SQL injection vulnerabilities in web application parameters

2026-05-01
auth-bypass
ソフトウェア開発者

Test for authentication and authorization flaws including credential attacks, session issues, and access control bypasses

2026-04-30
xss-testing
ソフトウェア開発者

Detect and exploit cross-site scripting vulnerabilities in web applications

2026-04-30
parameter-fuzzing
情報セキュリティアナリスト

Discover hidden parameters, test values, and identify input handling anomalies

2026-04-29
file-upload-testing
情報セキュリティアナリスト

File upload vulnerability testing — webshells, bypass, path traversal

2026-04-27
xxe-testing
情報セキュリティアナリスト

XML external entity injection for file read, SSRF, and DoS

2026-04-27
source-analysis
ソフトウェア開発者

Frontend source code analysis for hidden routes, API endpoints, and secrets

2026-04-26
directory-fuzzing
情報セキュリティアナリスト

Discover hidden directories, files, and endpoints on a web server

2026-03-30
port-scanning
情報セキュリティアナリスト

Discover open ports, running services, and their versions on a target

2026-03-30
subdomain-enumeration
情報セキュリティアナリスト

Subdomain discovery via subfinder, DNS brute-force, and passive sources

2026-03-30
user-enumeration
情報セキュリティアナリスト

Discover any interface (HTTP, WebSocket, GraphQL, gRPC, or other) that distinguishes between existing and non-existing users through any observable difference

2026-03-30
web-recon
情報セキュリティアナリスト

Enumerate web technologies, headers, endpoints, and metadata from a target

2026-03-23
command-injection
情報セキュリティアナリスト

OS command injection detection, exploitation, and filter bypass

2026-03-22
cors-testing
情報セキュリティアナリスト

CORS misconfiguration testing for data theft and access control bypass

2026-03-22
csrf-testing
情報セキュリティアナリスト

Cross-site request forgery testing for state-changing operations

2026-03-22
graphql-testing
情報セキュリティアナリスト

GraphQL security testing — introspection, injection, auth bypass, DoS

2026-03-22
request-smuggling
情報セキュリティアナリスト

HTTP request smuggling via CL.TE/TE.CL desync and cache poisoning

2026-03-22
info-disclosure-testing
情報セキュリティアナリスト

Information disclosure detection — error messages, files, headers, debug endpoints

2026-03-22
race-condition-testing
情報セキュリティアナリスト

Race condition and TOCTOU exploitation — parallel request attacks

2026-03-22
file-inclusion
情報セキュリティアナリスト

Detect and exploit local and remote file inclusion vulnerabilities for sensitive data access and code execution

2026-03-22
idor-testing
情報セキュリティアナリスト

Insecure direct object reference testing for broken access control

2026-03-22
open-redirect-testing
情報セキュリティアナリスト

Test for unvalidated redirects — URL parameters, login flows, OAuth callbacks that redirect to attacker-controlled domains

2026-03-22
ssti-testing
情報セキュリティアナリスト

Server-side template injection detection, engine identification, and RCE

2026-03-22
osint-recon
情報セキュリティアナリスト

Open-source intelligence gathering — CVE lookup, breach search, DNS history, social profiling

2026-03-21
deserialization-testing
情報セキュリティアナリスト

Insecure deserialization detection and gadget chain exploitation

2026-03-21
jwt-testing
情報セキュリティアナリスト

JWT token attack techniques — alg bypass, key confusion, claim tampering

2026-03-21
report-generation
情報セキュリティアナリスト

Engagement report structure and formatting guidelines

2026-03-21
ssrf-testing
情報セキュリティアナリスト

Detect and exploit server-side request forgery to access internal resources and cloud metadata

2026-03-21
websocket-testing
情報セキュリティアナリスト

WebSocket security testing — injection, auth bypass, hijacking

2026-03-21