Skip to main content
在 Manus 中运行任何 Skill
一键导入
GitHub 仓库

codex-attack

codex-attack 收录了来自 philo-groves 的 13 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。

已收集 skills
13
Stars
39
更新
2026-06-01
Forks
4
职业覆盖
1 个职业分类 · 已分类 100%
仓库浏览

这个仓库中的 skills

auto-triage
信息安全分析师

Build human-friendly, screen-recordable proof-of-concept reproduction kits from already proofed triage-verifier evidence. Use after triage-verifier accepts a finding as proofed, or when Codex needs to turn an agent-focused PoC, proof packet, request log, crash repro, or verifier artifact into direct step-based human reproduction artifacts for bounty triagers, researchers, auditors, or screen recordings.

2026-06-01
engagement-scope
信息安全分析师

Establish authorized engagement context, look up public bounty scope evidence, and route cyber tasks before using specialized skills. Use for any request to model security boundaries, review code vulnerabilities, inspect web or mobile apps, research CVEs, build fuzzers, reverse or debug binaries, or analyze exploit chains, especially when target authorization, bounty program scope, impact tolerance, or the desired deliverable is unclear.

2026-06-01
report-writer
信息安全分析师

Write submission-ready vulnerability reports, advisory drafts, bounty reports, disclosure notes, remediation summaries, and attachment bundles from proofed findings and verifier evidence. Use when Codex needs to turn finding-tracker IDs, triage-verifier proof packets, auto-triage human PoC kits, exploit-chain packets, screenshots, requests, logs, CVE/CWE/CVSS data, or Mermaid diagrams into a concise report for HackerOne, Bugcrowd, GitHub Security Advisories, coordinated disclosure, internal triage, or remediation handoff.

2026-06-01
triage-verifier
信息安全分析师

Verify confident security findings before they are marked proofed. Use when a finding has reached the `confident` state in finding-tracker and the current research chain has ended or plateaued, or when Codex needs to harden, rewrite, reproduce, package, or sanity-check a PoC for a bug bounty, audit, advisory, crash, CVE exposure, web/API issue, source-code finding, binary finding, fuzzing result, or exploit-chain finding. Do not interrupt productive investigation; use this as the proof gate before updating a finding to `proofed`.

2026-06-01
code-vulnerability-review
信息安全分析师

Perform authorized source-code vulnerability review, security patch review, exploitability triage, and remediation planning. Use when Codex needs to inspect codebases, pull requests, diffs, dependencies, configs, tests, or data flows for authn/authz flaws, injection, SSRF, deserialization, crypto misuse, secrets exposure, file/path bugs, concurrency issues, memory-safety issues, sandbox escapes, supply-chain risk, or bug bounty/code audit findings.

2026-06-01
exploit-chain-analysis
信息安全分析师

Analyze authorized exploit chains by combining tracked findings, confident or proofed issues, and de-escalated leads into higher-impact vulnerability hypotheses. Use when Codex needs to correlate findings, model preconditions and postconditions, consider de-escalated leads as conditional chain edges, create chain packets, update finding-tracker, or send chain findings through triage-verifier.

2026-06-01
subagent-orchestration
信息安全分析师

Plan and coordinate authorized multi-agent cyber workflows with explicit subagent roles, bounded assignments, tracker discipline, debate, deduplication, proof handoffs, and synthesis. Use when the user explicitly asks for subagents, parallel agents, delegation, debate, multiple reviewers, or staged agentic security work.

2026-06-01
finding-tracker
信息安全分析师

Maintain centralized security finding state across authorized cyber workflows. Use when Codex discovers, validates, proofs, de-escalates, updates, searches, deduplicates, summarizes, or hands off potential vulnerabilities, bug bounty findings, audit findings, exploitability leads, crash findings, web/API issues, CVE exposure decisions, fuzzing crashes, or reverse-engineering leads. Always use before adding a new discovered bug to check for duplicates and reduce repeated effort.

2026-05-13
fuzz-harness-builder
信息安全分析师

Selectively design, implement, run, and triage authorized fuzz harnesses for parsers, codecs, protocols, APIs, CLIs, libraries, native boundaries, kernels, and structured inputs when fuzzing is likely to justify its long-running cost. Use when Codex needs to build libFuzzer/AFL++/Honggfuzz/Centipede/cargo-fuzz/Go fuzz/Jazzer/Atheris/syzkaller-style harnesses, corpora, dictionaries, sanitizers, coverage runs, crash minimization, CI fuzzing, or fuzzing reports, especially after source review, binary reversing, or debugging has identified a fuzzable boundary worth sustained testing.

2026-05-06
binary-reversing
信息安全分析师

Reverse engineer authorized binaries and native artifacts through static analysis, disassembly, decompilation, strings, imports, symbols, file formats, firmware contents, protocols, config extraction, patch diffing, obfuscation triage, and security-relevant behavior recovery. Use when Codex needs to inspect ELF/Mach-O/PE files, shared libraries, firmware userspace binaries, native extensions, packed or stripped artifacts, proprietary protocols, license or crypto logic, malware-like samples in a defensive lab, or undocumented behavior without source code.

2026-05-06
binary-debugging
信息安全分析师

Debug authorized binaries, native crashes, core dumps, sanitizer reports, process state, runtime behavior, memory corruption, register state, symbols, dynamic loading, and exploitability evidence using debuggers and tracing tools. Use when Codex needs to inspect ELF/Mach-O/PE executables, shared libraries, firmware userspace binaries, native extensions, crash logs, minidumps, core files, GDB/LLDB/WinDbg sessions, ASAN/UBSAN/TSAN output, strace/ltrace/dtruss traces, or runtime behavior that cannot be resolved from source review alone.

2026-05-06
cve-research
信息安全分析师

Research CVEs, GHSAs, vendor advisories, affected versions, exploitability, exploitation status, severity, prioritization, mitigations, and remediation guidance from current authoritative vulnerability sources. Use when Codex needs to investigate a CVE or advisory ID, determine whether a product or dependency version is affected, compare NVD/CVE.org/vendor/OSV/GitHub advisory data, check CISA KEV or EPSS signals, triage patch urgency, prepare vulnerability intelligence summaries, or support authorized exploitability and remediation analysis.

2026-05-06
web-app-security-inspection
信息安全分析师

Perform authorized live or local web application security inspection using browser-visible behavior, HTTP traffic, API calls, authentication and authorization flows, session state, client-side storage, security headers, browser console evidence, and safe runtime validation. Use when Codex needs to inspect a web app, SPA, API-backed UI, admin panel, SaaS workflow, OAuth/OIDC flow, GraphQL/REST endpoint, WebSocket, upload/import/export feature, AI/agent web feature, or bug bounty target through a browser or controlled HTTP/runtime testing.

2026-05-06