Skip to main content

web-exploit-test

Localhost-only, stdlib evidence verifier: scan, JWT matrix, race controls.

소스 정보

저장소
Sekolah76/syadagentic
최근 소스 활동
2026년 8월 26일 15:28
감지된 SKILL.md 언어
판별 불가
스타
41
포크
13

설치 방법

기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.

소스 파일 검토

설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.

파일 탐색기
8 개 파일

SKILL.md 표시 중

SKILL.md
소스 지침 · 읽기 전용 미리보기
name
web-exploit-test
description
Localhost-only, stdlib evidence verifier: scan, JWT matrix, race controls.
# Web Exploit Test v2 Local fixture verification only. CLI rejects non-loopback target/allow-host/state URL. TLS strict unless `--insecure`; redirects never followed; request, timeout, worker, race, response bounds enforced. Atomic redacted evidence: schema `2.0`, mode `0600`, states `tested|skipped|error|candidate|verified`. No severity before verified impact. ```bash python3 scripts/verifier.py scan http://127.0.0.1:8080 --allow-host 127.0.0.1:8080 --modules headers,cors,methods,admin,exposed,xss,sqli,ssrf,ssti,traversal,redirect,https,info --budget 50 --test-budget 4 --output scan.json python3 scripts/verifier.py jwt http://127.0.0.1:8080/me --allow-host 127.0.0.1 --valid-token "$TOKEN" --budget 8 --output jwt.json python3 scripts/verifier.py race http://127.0.0.1:8080/action --allow-host 127.0.0.1:8080 --n 8 --workers 4 --serial 2 --state-url http://127.0.0.1:8080/state --state-pointer /counter --expected-delta 8 --max-delta 8 --budget 20 --output race.json python3 -m unittest discover -s tests -v ``` Scan berjalan sekuensial dengan `ModuleBudget` atomik per modul. `exposed` memakai baseline impossible-path plus signature Git/ZIP/SQLite/env. Kontrol kelas-spesifik tetap maksimal `candidate`; hanya artifact signature kuat dapat `verified`. Methods hanya observasi. JWT `alg:none` mempertahankan payload token valid; token malformed tidak diprobe. Race menghormati `--serial`; `verified` hanya bila `--state-pointer` plus `--expected-delta`/`--max-delta` terpenuhi. Failures are atomic structured evidence without traceback-only output. Limits: no DNS-name localhost aliases, DNS pinning, redirect following, browser XSS execution, SSRF callback, timing SQLi, destructive payloads, auth workflow, production targets. Offline `references/` remain research material only. Provenance: `PROVENANCE.md`, `NOTICE`, `MANIFEST.sha256`.
GitHub에서 보기