Skip to main content
yhy0
GitHub 创作者资料

yhy0

按仓库查看 5 个 GitHub 仓库中的 58 个已收集 skills。

已收集 skills
58
仓库
5
更新
2026年8月3日
仓库浏览

仓库与代表性 skills

ghsa-skill-builder
信息安全分析师

Use when building or updating vulnerability pattern Skills from multiple sources: GitHub Security Advisories (GHSA), HackerOne Hacktivity, or NVD. Triggers on keywords: GHSA, CVE, vulnerability skill, vuln pattern, update skills, security advisory, HackerOne,…

2026年3月14日
ghsa-skill-builder
信息安全分析师

Use when building or updating vulnerability pattern Skills from multiple sources: GitHub Security Advisories (GHSA), HackerOne Hacktivity, or NVD. Triggers on keywords: GHSA, CVE, vulnerability skill, vuln pattern, update skills, security advisory, HackerOne,…

2026年3月14日
go-vuln-auth-bypass
信息安全分析师

Use when auditing Go code involving authentication flows, RBAC policies, Kubernetes admission webhooks, JWT/OAuth token validation, or privilege escalation in cloud-native infrastructure. Covers CWE-287/863/269/284/285/862. Keywords: authentication bypass,…

2026年3月14日
go-vuln-crypto-tls
信息安全分析师

Use when auditing Go code involving TLS configuration, certificate validation, JWT token parsing, SAML assertion verification, webhook signature checking, or cryptographic operations. Covers CWE-295/347/345. Keywords: InsecureSkipVerify, TLS, mTLS,…

2026年3月14日
go-vuln-dos
信息安全分析师

Use when auditing Go code involving goroutine management, channel operations, HTTP request handling, resource allocation, or panic recovery. Covers CWE-400/770/476. Keywords: denial of service, goroutine leak, channel deadlock, panic recover, io.ReadAll,…

2026年3月14日
go-vuln-info-disclosure
信息安全分析师

Use when auditing Go code involving logging, error handling, HTTP response data, Kubernetes Secret management, or credential storage. Covers CWE-200/532/522/312/552. Keywords: information disclosure, credential leak, log exposure, Kubernetes Secret, json tag,…

2026年3月14日
go-vuln-injection
软件开发工程师

Use when auditing Go code involving OS command execution, SQL queries, template rendering, or child command invocation. Covers CWE-78/89/77/94/88. Keywords: command injection, SQL injection, exec.Command, os/exec, database/sql, text/template, html/template,…

2026年3月14日
go-vuln-path-traversal
软件开发工程师

Use when auditing Go code involving file path operations, archive extraction, symlink handling, container volume mounts, or HTTP file serving. Covers CWE-22/59. Keywords: path traversal, directory traversal, filepath.Join, symlink, archive extraction, zip…

2026年3月14日
已展示 8 / 28 个已收集 Skill。
ai-security
信息安全分析师

Use when facing AI security challenges involving prompt injection, LLM jailbreaks, or AI agent exploitation

2026年4月25日
binary
信息安全分析师

Use when facing binary exploitation (PWN) or reverse engineering challenges involving memory corruption, ROP chains, shellcode, binary analysis, decompilation, unpacking, or dynamic tracing

2026年4月25日
cryptography
信息安全分析师

Use when facing cryptography challenges involving cipher analysis, key recovery, mathematical attacks, or protocol weaknesses

2026年4月25日
file-transfer
网络与计算机系统管理员

Use when transferring files between remote environments and local Docker containers via litterbox.catbox.moe relay or base64 chunked fallback

2026年4月25日
forensics-misc
软件开发工程师

Use when facing digital forensics or misc challenges involving disk images, memory dumps, network captures, steganography, file format analysis, encoding puzzles, sandbox escapes, or archive manipulation

2026年4月25日
infra-exploit
信息安全分析师

Use when conducting penetration testing, post-exploitation, lateral movement, domain attacks, cloud exploitation (AWS/GCP/Azure), container escape, or Kubernetes cluster attacks

2026年4月25日
stagnation-recovery
其他计算机职业

Use when stuck, looping on same approach, making no progress after multiple tool calls, or receiving a stagnation warning from the system. Also trigger when you catch yourself retrying the same command with minor variations, getting repeated Permission denied…

2026年4月25日
web-security
信息安全分析师

Use when facing web security challenges involving injection, authentication bypass, IDOR, access control, CSRF, HRS, server-side vulnerabilities, or web application exploitation

2026年4月25日
已展示 8 / 21 个已收集 Skill。
已展示 5 / 5 个仓库
已展示全部仓库