원클릭으로
pentest-platform
pentest-platform에는 Seal-Re에서 수집한 skills 30개가 있으며, 저장소 수준 직업 범위와 사이트 내 skill 상세 페이지를 제공합니다.
이 저장소의 skills
Fast HTTP probing and lightweight fingerprinting using ProjectDiscovery httpx. Use for web recon with redirect-awareness and JSON output.
V5 样板 Micro-Skill:Pydantic 入参、micro_executor SDK、落盘 parsed.json、stderr S-06、stdout Agent 摘要 JSON(嵌入 raw_stdout)。
Build a basic understanding of the current project by scanning source code and available docs. Use when user asks for /init, project onboarding, quick repo familiarization, or initial architecture context.
Search the web using Baidu AI Search Engine (BDSE). Use for live information, documentation, or research topics.
Raw HTTP probing with curl. Use for custom method, headers and body requests in recon and validation.
Advanced web path scanner using multithreaded brute-force. Use for discovering hidden files, directories, and endpoints on web servers.
ETL + path-template dedupe + chunking + manifest. operation=prepare (default) or finalize. Context (Cookie/UA/tags) stored in manifest for nuclei.
Web fingerprint reconnaissance using EHole. Use for lightweight CMS/framework identification during recon.
ThinkPHP 5.x RCE exploit via invokefunction route (CVE-2018-20062). Targets PHP applications built on ThinkPHP 5.0/5.1 framework. Use after fingerprinting confirms ThinkPHP presence.
Apache Tomcat CVE-2017-12615 PUT arbitrary file upload RCE via JSP webshell. Targets Tomcat instances with HTTP PUT enabled and write permissions on the webroot.
Oracle WebLogic T3/IIOP deserialization RCE exploit (CVE-2023-21839, CVE-2020-14882). Targets Oracle WebLogic Server admin consoles and T3 listener ports.
Fastjson 1.2.24-1.2.47 JNDI injection RCE via autoType bypass (CVE-2019-14540). Targets Java REST APIs that deserialize user-supplied JSON using the Fastjson library.
Automated Jinja2 SSTI exploitation tool for bypassing WAF and detecting template injection vulnerabilities. Designed for CTF competitions with automatic parameter fuzzing and payload generation.
Directory and endpoint brute-force using ffuf. Use for web content discovery after basic fingerprinting.
Comprehensive network security scanner. Performs port scanning, service detection, vulnerability discovery, and asset enumeration. Use for quick reconnaissance and vulnerability assessment.
Basic HTTP fingerprint and header enumeration using curl. Use for web recon when only lightweight tooling is available.
JNDI injection server to deliver deserialization payloads via LDAP/RMI. Acts as the callback server for fastjson, log4shell, and WebLogic JNDI exploits.
Katana crawl (+ optional Dirsearch). Writes discovery/katana_urls.txt under WORKSPACE_ROOT/{task_id}/web-vuln/{run_id}/. Default depth=2, `-ct` crawl cap, `-ef` static extensions filter; pair with dispatcher → nuclei.
Penetration testing framework for exploit development and execution. Supports vulnerability scanning, exploitation, and post-exploitation. Use for comprehensive security testing and exploit testing.
Web vulnerability scanning using Nikto. Use in VULN_SCAN for common web misconfigurations and known issues.
Network discovery and service detection. Scans hosts for open ports, service versions, and basic scripts (e.g. -sV -sC). Use for reconnaissance and mapping target attack surface.
Nuclei scan using only `temlists/` as the template root (no bundled projectdiscovery/nuclei-templates); framework-routed matrix and phase-isolated tags (`safe-poc` / `exploit`).
让你的 AI 不敢摆烂。用大厂 PUA 话术穷尽一切方案。触发条件:(1) 任务失败 2+ 次或反复微调同一思路; (2) 即将说'我无法解决'、建议用户手动操作、未验证就归因环境; (3) 被动等待——不搜索、不读源码、只等指示; (4) 用户不满:'try harder'、'stop giving up'、'换个方法'、'为什么还不行'、'你再试试'、'你怎么又失败了'。适用于所有任务类型。首次失败或已知修复正在执行时不触发。
Secure Python execution sandbox for custom payload testing and HTTP requests. Allows agents to execute Python code with common libraries for penetration testing.
读取工作区内纯文本 URL 列表文件,返回 urls 数组(不合并 raw 日志,避免截断丢失)。
Read raw workspace artifact files by artifact_ref/path for PoC verification and false-positive validation.
Apache Shiro rememberMe deserialization RCE (CVE-2016-4437) with CommonsBeanutils chain. Targets Java web apps using Apache Shiro authentication framework.
Automated SQL injection detection and exploitation. Tests web URLs for SQLi with configurable risk/level. Use in exploit phase for validated targets.
Fingerprint web technologies with WhatWeb. Use for tech stack detection and quick web profiling.
Java deserialization payload generator for common gadget chains (CommonsBeanutils, CC1-CC6). Used as a helper skill to produce serialized Java payloads for delivery via other exploit skills.