Skip to main content
在 Manus 中运行任何 Skill
一键导入
GitHub 仓库

ethical-hacking-agent-skills

ethical-hacking-agent-skills 收录了来自 santosomar 的 13 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。

已收集 skills
13
Stars
20
更新
2026-04-24
Forks
6
职业覆盖
1 个职业分类 · 已分类 100%
仓库浏览

这个仓库中的 skills

pt-nuclei-template-creation
信息安全分析师

Creates Nuclei YAML templates for vulnerability detection across HTTP, DNS, TCP, SSL, and other protocols. Use when converting a confirmed vulnerability, misconfiguration, or exposure into a reusable automated check — for example, turning a manual finding into a detection rule, writing a CVE check, or codifying a technology fingerprint.

2026-04-24
pt-fuzzing-binary-protocol
信息安全分析师

Performs authorized fuzz testing of binary formats and network protocols to uncover parser vulnerabilities, memory safety defects, and denial-of-service conditions. Use when assessing protocol handlers, file parsers, and service robustness against malformed inputs.

2026-02-27
pt-fuzzing-web-api
信息安全分析师

Performs authorized fuzzing of web applications and APIs to discover input validation failures, parser bugs, and stability issues. Use when testing HTTP endpoints, request parameters, payload handling, and error behavior under malformed or unexpected inputs.

2026-02-27
pt-lotl-techniques
信息安全分析师

Demonstrates Living-off-the-Land (LotL) techniques using native OS tools to simulate realistic threat actor behavior during authorized penetration tests. Use when proving attack feasibility without custom malware, testing detection coverage, and validating what a real adversary could achieve with only built-in system capabilities.

2026-02-27
pt-post-exploitation
信息安全分析师

Performs authorized post-exploitation activities to assess impact, lateral movement paths, credential exposure, and detection gaps after initial compromise. Use when a foothold has been validated and the test requires controlled impact expansion analysis.

2026-02-27
pt-report-creation
信息安全分析师

Creates penetration test deliverables for executive and technical audiences, including prioritized findings and remediation plans. Use when drafting, structuring, or finalizing pen test reports from collected evidence.

2026-02-27
pt-analysis-reporting
信息安全分析师

Produces penetration test reports with executive summary, technical findings, and remediation guidance. Use when consolidating test evidence, prioritizing risk, and preparing stakeholder-ready deliverables.

2026-02-27
pt-embedded-device-assessment
信息安全分析师

Performs authorized security assessment of embedded and IoT devices across hardware, firmware, interfaces, and update mechanisms. Use when testing device boot flows, debug interfaces, firmware integrity, and local/network attack surfaces.

2026-02-27
pt-gaining-access
信息安全分析师

Guides controlled exploitation of validated vulnerabilities to measure real-world impact. Use when the user requests proof-of-concept validation, privilege escalation testing, or attack path confirmation in an authorized environment.

2026-02-27
pt-maintaining-access
信息安全分析师

Evaluates whether an attacker could retain foothold and move laterally after initial compromise, within strict authorization limits. Use when testing persistence, session resilience, and detection/response effectiveness during a pen test.

2026-02-27
pt-planning-recon
信息安全分析师

Defines penetration test scope and performs authorized reconnaissance using passive and active methods. Use when planning a test engagement, collecting target intelligence, building asset inventories, or preparing recon findings.

2026-02-27
pt-scanning
信息安全分析师

Performs authorized security scanning using static, dynamic, and vulnerability-focused methods. Use when mapping exposed services, profiling application behavior, and identifying known weaknesses for validation.

2026-02-27
pt-web-application-assessment
信息安全分析师

Performs authorized web application and API penetration testing with focus on OWASP-style risks and business logic flaws. Use when assessing websites, web APIs, authentication flows, session handling, and input validation.

2026-02-27