Skip to main content
在 Manus 中运行任何 Skill
一键导入
GitHub 仓库

Tesserin-pro

Tesserin-pro 收录了来自 Samurai-goose 的 16 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。

已收集 skills
16
Stars
5
更新
2026-03-12
Forks
6
职业覆盖
2 个职业分类 · 已分类 100%
仓库浏览

这个仓库中的 skills

active-directory-and-identity-audit
信息安全分析师

Audit Active Directory, LDAP, and enterprise identity infrastructure for misconfigurations, privilege escalation paths, Kerberos weaknesses, trust relationship abuse, and credential exposure.

2026-03-12
api-security-review
信息安全分析师

API-specific security testing for REST, GraphQL, WebSocket, and gRPC endpoints. Covers authentication, authorization, injection, rate limiting, mass assignment, and API-specific attack patterns.

2026-03-12
bug-bounty-triage
信息安全分析师

Intake, deduplication, severity assignment, and prioritization of security findings for bug bounty and pentest engagements. Processes raw findings into actionable triaged items.

2026-03-12
ci-cd-supply-chain-security
信息安全分析师

Audit CI/CD pipelines and software supply chains for poisoning vectors, secret exposure, artifact tampering, dependency confusion, and build environment compromise. Covers GitHub Actions, GitLab CI, Jenkins, and container build pipelines.

2026-03-12
cloud-config-audit
信息安全分析师

Audit cloud infrastructure configuration for security misconfigurations across AWS, Azure, and GCP. Covers IAM, storage, networking, compute, and logging. Reviews IaC templates (Terraform, CloudFormation, Pulumi).

2026-03-12
container-and-runtime-security
信息安全分析师

Assess container runtime security including escape paths, kernel exploitation, capability abuse, namespace breakouts, and orchestration runtime issues beyond static configuration review.

2026-03-12
dependency-and-secret-audit
信息安全分析师

Audit third-party dependencies for known vulnerabilities and detect hardcoded secrets, API keys, and credentials in source code, configuration, and git history.

2026-03-12
evidence-and-reporting
信息安全分析师

Compile, format, and generate security assessment reports from triaged findings. Produces consistent, professional reports with executive summaries, finding details, remediation guidance, and validation notes.

2026-03-12
exploit-validation
信息安全分析师

Develop and execute proof-of-concept exploits to validate suspected vulnerabilities. Confirms exploitability, measures real impact, and produces reproducible evidence for confirmed findings.

2026-03-12
indepth-recon-analysis
信息安全分析师

Deep reconnaissance review and attack surface mapping. Analyzes gathered recon data to identify exposed services, entry points, technology stacks, and potential attack vectors.

2026-03-12
mobile-security-assessment
信息安全分析师

Security assessment of iOS and Android mobile applications. Covers OWASP Mobile Top 10, reverse engineering, runtime manipulation, data storage, network security, certificate pinning bypass, and platform-specific attack patterns.

2026-03-12
network-infrastructure-pentest
信息安全分析师

Network-layer security assessment covering segmentation validation, service enumeration, firewall rule analysis, protocol attacks, and infrastructure exposure testing.

2026-03-12
secure-code-review
软件质量保证分析师与测试员

Source-level vulnerability hunting. Systematic review of application source code for injection flaws, auth bypasses, logic bugs, cryptographic weaknesses, and unsafe patterns. Operates on code files within the workspace.

2026-03-12
security-governance
信息安全分析师

Establishes engagement rules, authorization boundaries, and operational guardrails for all security review skills. Must be invoked before any assessment work begins.

2026-03-12
threat-modeling
信息安全分析师

Proactive threat identification using structured frameworks (STRIDE, PASTA). Models data flows, trust boundaries, and threat actors to prioritize security testing and contextualize findings with business risk.

2026-03-12
web-misconfig-review
信息安全分析师

Review web server, application, and infrastructure configuration for security misconfigurations. Covers headers, TLS, CORS, error handling, directory exposure, and deployment hygiene.

2026-03-12