Skip to main content
在 Manus 中运行任何 Skill
一键导入

rate-limit-hunter

星标15
分支7
更新时间2026年6月28日 16:46

Tests APIs and sensitive features for missing or weak rate limiting - credential-stuffing resistance, MFA code brute-force, SMS / email amplification, oversized-payload resource exhaustion, and IP / session rotation evasion. Use when the target has login / password-reset / MFA / signup / SMS-trigger endpoints and `api-recon`'s auth inventory shows no `X-RateLimit-*` response headers; when the orchestrator identifies high-cost operations; or when cross-referencing a `auth-flaw-hunter` lockout finding. Produces findings with CWE-307 / CWE-770 / CWE-400 mapping and throttle / captcha / resource-limit remediation. Defensive testing only, against assets listed in .claude/security-scope.yaml - service_affecting: true.

安装

用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。

SKILL.md
readonly