用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/Netw0rkNoob/VulnClaw --skill rapid-checklist命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
| name | rapid-checklist |
| description | 渗透速查与Payload — 快速Payload家族、绕过提醒、验证顺序、常见测试卡片,适用于已知测试方向后快速查找 |
仅在路由已明确后使用。本 Skill 用于快速查找,不替代方法论或工作流选择。
pentest-flowclient-reverseCTF 题目优先用
ctf-web/ctf-crypto/ctf-miscSkill,以下为快速卡片:
| 场景 | 快速定位 |
|---|---|
| PHP 弱比较 → 0e 开头 MD5 值 | ctf-web → php-bypass-cheatsheet.md |
| 命令注入空格绕过 → ${IFS}/$IFS$9/< | ctf-web → command-injection-bypass.md |
| eval 无回显 → 写文件/DNS 外带 | ctf-web → eval-and-rce-techniques.md |
| RSA 小指数 → 立方根/Coppersmith | ctf-crypto → rsa-attacks-cheatsheet.md |
Python Jail → __import__/func_globals | ctf-misc → python-jail-escape.md |
| 编码链 → base64→hex→ROT13 多层 | ctf-misc → encoding-chain-reference.md |
', ", ), 布尔差异, 时间差异, 报错差异<script>, <img onerror>, javascript:, DOM sink;id, |id, `id`, $(id){{7*7}}, ${7*7}, <%= 7*7 %>, 模板引擎指纹<!ENTITY>, 参数实体, OOB 外带client-reverse 稳定重放client-reverse runtime-first 路径intranet-pentest-advancedpentest-toolsreferences/08-rapid-checklists-and-payloads.md — 速查与 Payload 整合参考references/testing-methodology.md — 测试方法论OSINT 开源情报收集知识库 — 四维信息收集模型(服务器→网站→域名→人员),维度四(人员信息)条件触发
Domain routing and boundary guidance for authorized Active Directory red-team security testing, including Kerberos attacks, domain privilege escalation, lateral movement, and GPO abuse. Use when a task belongs to the AD testing domain and needs scope, evidence, pivot, or exit criteria.
Domain routing and boundary guidance for authorized API security testing, including BOLA/IDOR, authentication bypass, mass assignment, missing rate limits, and GraphQL issues. Use when a task belongs to the API testing domain and needs scope, evidence, pivot, or exit criteria.
基于 SOC 职业分类