Skip to main content
在 Manus 中运行任何 Skill
一键导入
GitHub 仓库

security-skill

security-skill 收录了来自 woohyun212 的 58 个 skills,并提供仓库级职业覆盖和站内 skill 详情页。

已收集 skills
58
Stars
20
更新
2026-04-15
Forks
1
职业覆盖
2 个职业分类 · 已分类 100%
仓库浏览

这个仓库中的 skills

isms-checklist
信息安全分析师

Interactive gap analysis against Korea's ISMS-P 102-control certification framework (management, protection, personal information)

2026-04-15
log-analysis
信息安全分析师

Security log analysis and anomaly detection for access, auth, and syslog files

2026-04-15
malware-analysis
信息安全分析师

Analyze suspicious files through triage/static/dynamic/code phases to produce IOCs, YARA/Sigma rules, and MITRE ATT&CK mappings

2026-04-15
malware-hash
信息安全分析师

File hash reputation lookup via VirusTotal API v3 for MD5/SHA1/SHA256 detection ratio, threat classification, and vendor results

2026-04-15
owasp-check
信息安全分析师

OWASP Top 10 (2021) checklist-based inspection and compliance matrix generation

2026-04-15
building-secure-contracts
信息安全分析师

Multi-chain smart contract security for Solana, Algorand, Cairo, Cosmos, Substrate, and TON with pre-audit readiness checks

2026-04-14
constant-time-analysis
信息安全分析师

Detect timing side-channel vulnerabilities in cryptographic code caused by secret-dependent branching and memory access patterns

2026-04-14
differential-review
信息安全分析师

Security-focused git diff analysis to detect regressions, new vulnerabilities, and unsafe changes in code reviews

2026-04-14
entry-point-analyzer
信息安全分析师

Identify and classify state-changing entry points in smart contracts and applications to map the attack surface

2026-04-14
insecure-defaults
信息安全分析师

Detect insecure default configurations including weak crypto, fail-open patterns, default credentials, and unsafe framework settings

2026-04-14
property-based-testing
软件质量保证分析师与测试员

Property-based fuzzing and testing to find security edge cases in crypto, smart contracts, and parsers across multiple languages

2026-04-14
spec-to-code-compliance
软件质量保证分析师与测试员

Verify code implementation matches security specifications, detecting deviations that could introduce vulnerabilities

2026-04-14
testing-handbook
信息安全分析师

Security testing methodology using fuzzers (AFL++, libFuzzer), sanitizers (ASan, MSan, UBSan), and static analysis for vulnerability discovery

2026-04-14
ad-pentest
信息安全分析师

Active Directory pentest with BloodHound attack path analysis, Kerberos/ADCS attacks, credential harvesting, and lateral movement

2026-04-14
bug-bounty-methodology
信息安全分析师

Guided bug bounty hunting session with recon, mapping, discovery, exploitation, and reporting phases with escalation routing

2026-04-14
bug-bounty-validation
信息安全分析师

Pre-submission validation for bug bounty findings with scope/impact/exploitability gates, CVSS scoring, and submit/kill verdict

2026-04-14
cert-transparency
信息安全分析师

Certificate Transparency log search via crt.sh API to discover subdomains and certificates

2026-04-14
cloud-pentest
信息安全分析师

Multi-cloud CSPM assessment using ScoutSuite/Prowler with IAM privilege escalation, storage exposure, and network posture for AWS/Azure/GCP

2026-04-14
cors-check
信息安全分析师

Detect CORS misconfiguration by testing various Origin headers and analyzing Access-Control responses

2026-04-14
cve-lookup
信息安全分析师

CVE detail lookup from NVD API v2 with CVSS scores, vectors, and affected products

2026-04-14
dependency-audit
信息安全分析师

Dependency vulnerability audit across Node.js, Python, and Go ecosystems

2026-04-14
devsecops-pipeline
信息安全分析师

Assess CI/CD pipeline security maturity, identify DevSecOps gaps, and generate GitHub Actions/GitLab CI configs with security gates

2026-04-14
dns-recon
信息安全分析师

DNS record reconnaissance and zone transfer attempts using dig, host, and nslookup

2026-04-14
encoding-toolkit
信息安全分析师

Encode/decode strings (Base64, URL, Hex, HTML, ROT13, JWT) for payload transformation, WAF bypass, and encoded data analysis

2026-04-14
exploit-chain-building
信息安全分析师

Escalate confirmed low/medium findings into high-impact exploit chains (A→B→C) with combined CVSS scoring

2026-04-14
hash-identify
信息安全分析师

Identify hash algorithm type from a hash string and optionally verify against a known plaintext

2026-04-14
llm-ai-security
信息安全分析师

LLM/AI application security testing for prompt injection, system prompt leakage, tool abuse, and output handling per OWASP AI Security Top 10

2026-04-14
mobile-pentest
信息安全分析师

Mobile app security testing with Frida instrumentation, OWASP MASVS compliance, and SSL pinning/root detection bypass for Android/iOS

2026-04-14
nuclei-scan
信息安全分析师

Nuclei template-based vulnerability scanning with severity filtering and structured output

2026-04-14
osint-email
信息安全分析师

Email-based OSINT collection including breach database checks and social account enumeration

2026-04-14
pentest-report
信息安全分析师

Pentest report authoring with executive summary, CVSS-scored findings, attack narrative, and remediation roadmap (writing methodology)

2026-04-14
port-scan
信息安全分析师

Port scanning and service detection with nmap for authorized security assessments

2026-04-14
secret-scan
信息安全分析师

Secret and credential detection in source code and git history using trufflehog or gitleaks

2026-04-14
secure-code-review
信息安全分析师

Security code review across input validation, auth, injection, crypto, error handling, dependencies, and concurrency with CWE mapping

2026-04-14
siem-rule
信息安全分析师

Create and convert SIEM detection rules (Sigma/Splunk SPL/Elastic KQL/Sentinel KQL) from threat objectives, IOCs, or CVE reports

2026-04-14
subdomain-enum
信息安全分析师

Subdomain enumeration using subfinder and amass to discover attack surface

2026-04-14
subdomain-takeover
信息安全分析师

Subdomain takeover detection and verification for dangling DNS records

2026-04-14
supply-chain-audit
信息安全分析师

Supply chain security audit with SCA scanning (trivy/grype), SLSA compliance assessment, and SBOM generation (CycloneDX/SPDX)

2026-04-14
threat-model
信息安全分析师

Structured threat modeling producing threat catalog with STRIDE categorization, DREAD risk scores, and prioritized mitigation roadmap

2026-04-14
waf-detect
信息安全分析师

Detect the presence and type of a Web Application Firewall using wafw00f or manual fingerprinting

2026-04-14
当前展示该仓库 Top 40 / 58 个已收集 skills。