Skip to main content

PentesterFlow/agent

SkillsMP는 PentesterFlow/agent에서 11개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

최근 기록된 소스 활동
SkillsMP 카탈로그 업데이트
수집된 skills
11
GitHub 스타
1,316
GitHub 포크
241

이 저장소의 skills

직업 카테고리 2개 · 100% 분류됨

수집된 skill 11개 중 11개를 표시합니다.

직업 분류
정보 보안 분석가
설명

Insecure-deserialization playbook — fingerprint the language/format (Java serialized, .NET BinaryFormatter, Python pickle, PHP unserialize, Node serialize, YAML/JSON-with-types), then build a working gadget chain with ysoserial / ysoserial.net / phpggc /…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

GraphQL pentest playbook — find the endpoint, dump the schema (introspection or field-suggestion fallback), then test for authorization gaps, query batching, alias overload, depth-based DoS, and SQLi/NoSQLi in resolver arguments. Use when the target exposes a…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

JWT attack playbook — algorithm confusion (alg=none, HS/RS confusion), kid path traversal/SQLi, jku/x5u SSRF, weak HS256 cracking, and embedded JWK trickery. Use when the target uses JWTs for auth (header.payload.signature).

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Race condition / TOCTOU playbook — limit overrun (one-time codes used twice, gift cards spent twice), single-packet attack (last-byte sync) to force parallel processing, and state-confusion races (file upload + read, order before payment). Use when…

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

External recon playbook for a web target — subdomain enumeration, live-host probing, tech fingerprinting, and a first pass at content discovery. Use when the user gives you a root domain or apex and wants attack surface mapping.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Deep-dive SSRF testing — bypass filters, hit cloud metadata, chain to RCE/credential disclosure. Use when a target parameter clearly accepts a URL or hostname.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Server-Side Template Injection — fingerprint the engine first (Jinja2 / Twig / Velocity / Freemarker / ERB / Smarty / Mako / Handlebars / Pug), then escalate the engine-specific primitive to RCE or sandbox escape. Use when user input is reflected through a…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Supabase / PostgREST Row-Level-Security playbook — pull the anon (or leaked service_role) key out of the frontend JS, map tables from the auto-generated OpenAPI spec, test anonymous RLS READ disclosures (PII/secret leaks), and anonymous RLS WRITE abuse…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Subdomain takeover playbook — sweep subdomains for dangling CNAMEs / NS records pointing at unclaimed third-party resources (GitHub Pages, S3, Heroku, Azure, Netlify, Shopify, ...), confirm with the engine's HTTP fingerprint, then prove impact by claiming the…

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

Web vulnerability hunting playbook. Use after recon, when you have specific hosts/endpoints to test for IDOR/BAC, injection, auth flaws, SSRF, and known CVEs. Emphasizes real PoC + concrete impact.

원문 언어: 영어

업데이트
직업 분류
소프트웨어 개발자
설명

One line on what this playbook does, then a "Use when ..." clause so the agent knows when to load it (e.g. "Use when the target exposes X / you see Y in requests"). Max 1024 chars. This description is the ONLY thing the model sees until it loads the skill —…

원문 언어: 영어

업데이트
수집된 skill 11개 중 11개를 표시합니다.