Skip to main content
vigolium
GitHub 创作者资料

vigolium

按仓库查看 4 个 GitHub 仓库中的 35 个已收集 skills。

已收集 skills
35
仓库
4
更新
2026年8月19日
仓库浏览

仓库与代表性 skills

vigolium-scanner
信息安全分析师

Use when operating the vigolium CLI for web vulnerability scanning, security testing, or traffic analysis. Covers scanning a URL/spec/raw request, running AI agent scans (autopilot, swarm, audit, query), triaging findings, confirming them with replay/fuzz,…

2026年8月19日
audit
信息安全分析师

Use when performing repository security analysis that combines application/attack-surface modeling and, depending on mode, advisory intelligence, static analysis, manual exploit-path review, false-positive elimination, PoC construction, and reporting. Applies…

2026年7月17日
vigolium-audit
信息安全分析师

Use when the user asks to run a security audit, find vulnerabilities in a repo, "audit this codebase", check for exploitable bugs, or otherwise drive `vigolium-audit` — the autonomous multi-agent security auditor. Covers install, mode selection (lite /…

2026年7月11日
last30days
其他业务运营专家

Researches a topic from the last 30 days across the web, Reddit, and X, surfacing real discussions with engagement metrics and synthesizing them into actionable insights. In an audit, use it for recent domain attack research — newly disclosed CVEs, fresh…

2026年6月11日
idor-blast-radius
信息安全分析师

When you find an Insecure Direct Object Reference (a URL/body/header parameter that lets you read or write another user's or another tenant's object), discover the ID space, prove the access is unauthorized, quantify the blast radius (how many records…

2026年6月5日
xss-browser-confirm
信息安全分析师

Turn a suspected Cross-Site Scripting reflection or DOM sink into proof of JavaScript execution by firing a uniquely-tagged dialog in a real headless browser via the browser_probe tool — not by string-matching the response. Covers reflected, stored, and…

2026年6月5日
audit-auth
信息安全分析师

Audit authentication and session-management code for common issues — weak JWT config, session fixation, password-handling flaws, insecure cookies, broken OAuth flows, and missing auth checks on routes. Use when the user asks to review auth code or when…

2026年5月23日
command-injection-rce
信息安全分析师

Turn suspected OS command injection (a parameter that lands in a shell or a child process) into proof of remote code execution via an OAST callback, plus one safe demonstration of follow-on impact (read a file, list users, env dump). Use when a parameter…

2026年5月23日
已展示 8 / 29 个已收集 Skill。
已展示 4 / 4 个仓库
已展示全部仓库