Skip to main content
在 Manus 中运行任何 Skill
一键导入
GitHub 仓库

yunjing

yunjing 收录了来自 2099383411 的 15 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。

已收集 skills
15
Stars
3
更新
2026-06-24
Forks
0
职业覆盖
1 个职业分类 · 已分类 100%
仓库浏览

这个仓库中的 skills

awesome-pentest
信息安全分析师

Browse curated penetration testing resources and exploit databases. Use when planning security audits, researching vulns, or building toolkits.

2026-06-24
client-side-pentest
信息安全分析师

Perform a thorough client-side / browser-facing security assessment of a target web application. Use this skill whenever the user asks to pentest, audit, or review the security of a website or web app from the browser/frontend perspective, mentions client-side vulnerabilities (XSS, CORS, open redirect, clickjacking, prototype pollution, JWT leakage, source maps, etc.), wants to find sensitive data exposed in JavaScript bundles or client code, or asks for a security report on front-end attack surface. Trigger even if the user just says "test the security of this site", "find vulnerabilities in this web app", or "run a pentest on the frontend".

2026-06-24
hexstrike
信息安全分析师

Cybersecurity assistant for CTF challenges, penetration testing, network recon, vulnerability assessment, and security research. Use when: (1) solving CTF challenges (web, crypto, pwn, forensics, rev, OSINT, misc), (2) performing network reconnaissance or port scanning, (3) web application security testing, (4) vulnerability scanning and assessment, (5) binary analysis or reverse engineering, (6) password cracking or hash identification, (7) forensics analysis (file, memory, network, steganography), (8) cloud security assessment (AWS, GCP, K8s, containers), (9) OSINT gathering, (10) any offensive security or red team task. Triggers on: CTF, capture the flag, pentest, recon, nmap, exploit, vulnerability, reverse engineering, forensics, steganography, hash crack, brute force, SQL injection, XSS, buffer overflow, ROP, binary exploitation, OSINT, bug bounty, security audit, cloud security.

2026-06-24
net-vuln-scan
信息安全分析师

网络安全漏洞检测工具。用于检测本地网络和主机的常见安全漏洞,包括: (1) 开放端口检测与风险评估 (2) 弱密码和默认凭证检测 (3) SSL/TLS 证书问题 (4) 常见服务漏洞检测 (5) 网络配置安全检查 (6) 敏感端口暴露检测。 适用于:安全审计、渗透测试前自查、系统加固、服务器上线检查。 注意:仅用于授权的安全检测,禁止未授权扫描他人系统。

2026-06-24
nmap-pentest-scans
信息安全分析师

Plan and orchestrate authorized Nmap host discovery, port and service enumeration, NSE profiling, and reporting artifacts for in-scope targets.

2026-06-24
penetration-tester
信息安全分析师

Expert penetration tester specializing in ethical hacking, vulnerability assessment, and security testing. Masters offensive security techniques, exploit development, and comprehensive security assessments with focus on identifying and validating security weaknesses.

2026-06-24
pentest-active-directory
信息安全分析师

Assess Active Directory identity attack paths including roasting, relay, and delegation abuse.

2026-06-24
pentest-api-attacker
信息安全分析师

Test APIs against OWASP API Security Top 10 including discovery, auth abuse, and protocol-specific checks.

2026-06-24
pentest-auth-bypass
信息安全分析师

Test authentication and session management controls for bypass and account takeover scenarios.

2026-06-24
pentest-c2-operator
信息安全分析师

Set up authorized C2 simulation workflows and measure defensive detection outcomes.

2026-06-24
pentest-commands
信息安全分析师

Essential penetration testing command reference. Quick lookup for nmap, Metasploit, hydra, john, nikto, gobuster, and other offensive security tools. Covers reconnaissance, exploitation, post-exploitation, and lateral movement.

2026-06-24
pentest-workbench
信息安全分析师

Comprehensive offensive security workflow for bug bounty, vulnerability assessment, penetration testing, and exploitation. Use when performing security testing, analyzing vulnerable targets, conducting privilege escalation, building exploits, or running reconnaissance. Covers: TCP buffer overflows (vulnserver), web application testing (VulnerableWordpress/WPScan), honeypot analysis (Cowrie), GTFOBins/LOLBAS privesc, pwn.college fundamentals, and offensive toolchain automation. Triggers on: run a pentest, exploit this, buffer overflow, privesc, OSCP, CTF, bug bounty, vulnerability assessment, rev shell, test this target.

2026-06-24
prts-sandbox
信息安全分析师

Isolated Kali Linux sandbox for running pentest tools and risky commands safely.

2026-06-24
security-reviewer
信息安全分析师

Use when conducting security audits, reviewing code for vulnerabilities, or analyzing infrastructure security. Invoke for SAST scans, penetration testing, DevSecOps practices, cloud security reviews.

2026-06-24
shannon-pentest
信息安全分析师

AI-driven white-box penetration testing methodology adapted from Shannon (Keygraph). Follows a 5-phase pipeline (Pre-Recon, Recon, Vulnerability Analysis, Exploitation, Reporting) with structured deliverables. Use when the user asks for security audit, penetration testing, vulnerability assessment, or exploit validation of web applications, APIs, or source code.

2026-06-24