一键导入
essential-tools
Core pentesting tools and methodology - Burp Suite usage, Playwright automation, testing methodology, and professional reporting standards.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
菜单
Core pentesting tools and methodology - Burp Suite usage, Playwright automation, testing methodology, and professional reporting standards.
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
基于 SOC 职业分类
Systematic IDOR / BOLA hunting methodology. Use when testing any endpoint that accepts an ID, UUID, slug, filename, or reference to a user-owned object.
SQL injection hunting methodology across error-based, union, blind boolean, and time-based variants. Use when testing any input that might reach a database.
SSRF hunting methodology with OOB detection via interactsh, cloud metadata targets, and blind SSRF techniques. Use on any feature that accepts a URL, hostname, or external reference.
XSS hunting methodology — reflected, stored, and DOM — with context-aware payloads. Use when testing any input that could reach a browser.
OWASP Top 10 (2021) and API Top 10 (2023) quick reference with attack patterns, test ideas, and CWE mappings. Load when hunting, code-reviewing for security, or writing bug bounty reports.
Bug bounty report generation — structure, triager-friendly writing, CVSS scoring, and chain reporting. Use when finalizing a finding for submission.
| name | essential-tools |
| description | Core pentesting tools and methodology - Burp Suite usage, Playwright automation, testing methodology, and professional reporting standards. |
Core tools, methodology, and reporting standards for penetration testing.
| Component | Purpose |
|---|---|
| Burp Suite | Proxy, scanner, intruder, repeater, sequencer |
| Playwright | Browser automation, evidence capture, SPA testing |
| Methodology | PTES, OWASP WSTG, attack prioritization |
| Reporting | Professional report templates, DOCX generation |
reference/essential-skills*.md - Burp Suite techniques and web security testing methodologyreference/playwright-automation.md - Playwright MCP usage for pentestingreference/web-application-attacks.md - Web application attack methodologyreference/PROFESSIONAL_REPORT_STANDARD.md - Finding quality standards, compliance mapping, and pre-delivery checklist (report structure is in coordination skill)