Skip to main content
在 Manus 中运行任何 Skill
一键导入
$pwd:
xalgord
GitHub 创作者资料

xalgord

按仓库查看 1 个 GitHub 仓库中的 767 个已收集 skills,并展示近似职业覆盖。

已收集 skills
767
仓库
1
职业领域
3
更新
2026-05-07
仓库浏览

仓库与代表性 skills

#001
xalgorix
767 个 skills52693更新于 2026-05-07
占该创作者 100%
performing-zero-day-vulnerability-discovery
信息安全分析师

Systematic methodology for discovering novel vulnerabilities through manual code auditing, fuzzing, reverse engineering, and creative attack chaining during authorized security assessments.

2026-05-07
performing-exploit-verification
信息安全分析师

Systematic methodology for safely confirming and documenting exploited vulnerabilities with reproducible proof, ensuring zero false positives before reporting.

2026-05-07
exploiting-file-upload-vulnerabilities
信息安全分析师

Identifying and exploiting insecure file upload functionality to achieve remote code execution, stored XSS, path traversal, and denial of service during authorized penetration tests.

2026-05-07
exploiting-subdomain-takeover-vulnerabilities
信息安全分析师

Identifying and exploiting dangling DNS records pointing to unclaimed cloud services, enabling subdomain takeover for phishing, cookie stealing, and authentication bypass during authorized penetration tests.

2026-05-07
performing-cms-specific-security-testing
信息安全分析师

Testing WordPress, Drupal, Joomla, and other CMS platforms for known vulnerabilities, plugin/theme exploits, misconfigured permissions, and CMS-specific attack vectors during authorized penetration tests.

2026-05-07
performing-email-security-testing
信息安全分析师

Offensive email security assessment covering SMTP open relay, SPF/DKIM/DMARC bypass, email header injection, and email-based attack vectors during authorized penetration tests.

2026-05-07
performing-firmware-extraction-with-binwalk
信息安全分析师

Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery. Activates for requests involving firmware reverse engineering, IoT device analysis, embedded system security assessment, or router/camera firmware extraction.

2026-04-27
detecting-ai-model-prompt-injection-attacks
软件开发工程师

Detects prompt injection attacks targeting LLM-based applications using a multi-layered defense combining regex pattern matching for known attack signatures, heuristic scoring for structural anomalies, and transformer-based classification with DeBERTa models. The detector analyzes user inputs before they reach the LLM, flagging direct injections (system prompt overrides, role-play escapes, instruction hijacking) and indirect injections (encoded payloads, multi-language obfuscation, delimiter-based escapes). Based on the OWASP LLM Top 10 (LLM01:2025 Prompt Injection) and Simon Willison's prompt injection taxonomy. Activates for requests involving prompt injection detection, LLM input sanitization, AI security scanning, or prompt attack classification.

2026-04-27
当前展示该仓库 Top 8 / 767 个已收集 skills。
已展示 1 / 1 个仓库
已展示全部仓库