Skip to main content
在 Manus 中运行任何 Skill
一键导入
$pwd:
yhy0
GitHub 创作者资料

yhy0

按仓库查看 3 个 GitHub 仓库中的 51 个已收集 skills,并展示近似职业覆盖。

已收集 skills
51
仓库
3
职业领域
1
更新
2026-04-25
职业覆盖
该创作者主要覆盖的职业大类。
仓库浏览

仓库与代表性 skills

#001
ghsa-skill-builder
28 个 skills7111更新于 2026-03-14
占该创作者 55%
ghsa-skill-builder
信息安全分析师

Use when building or updating vulnerability pattern Skills from multiple sources: GitHub Security Advisories (GHSA), HackerOne Hacktivity, or NVD. Triggers on keywords: GHSA, CVE, vulnerability skill, vuln pattern, update skills, security advisory, HackerOne, H1, hacktivity, pentest skill, bug bounty, check for updates.

2026-03-14
ghsa-skill-builder
信息安全分析师

Use when building or updating vulnerability pattern Skills from multiple sources: GitHub Security Advisories (GHSA), HackerOne Hacktivity, or NVD. Triggers on keywords: GHSA, CVE, vulnerability skill, vuln pattern, update skills, security advisory, HackerOne, H1, hacktivity, pentest skill, bug bounty, check for updates.

2026-03-14
go-vuln-auth-bypass
信息安全分析师

Use when auditing Go code involving authentication flows, RBAC policies, Kubernetes admission webhooks, JWT/OAuth token validation, or privilege escalation in cloud-native infrastructure. Covers CWE-287/863/269/284/285/862. Keywords: authentication bypass, authorization bypass, RBAC, admission webhook, JWT, OAuth, privilege escalation, Rancher, Kyverno, impersonation, namespace isolation, middleware auth

2026-03-14
go-vuln-crypto-tls
信息安全分析师

Use when auditing Go code involving TLS configuration, certificate validation, JWT token parsing, SAML assertion verification, webhook signature checking, or cryptographic operations. Covers CWE-295/347/345. Keywords: InsecureSkipVerify, TLS, mTLS, certificate validation, JWT algorithm, SAML signature, cosign, sigstore, hmac.Equal, X.509, webhook HMAC

2026-03-14
go-vuln-dos
信息安全分析师

Use when auditing Go code involving goroutine management, channel operations, HTTP request handling, resource allocation, or panic recovery. Covers CWE-400/770/476. Keywords: denial of service, goroutine leak, channel deadlock, panic recover, io.ReadAll, resource exhaustion, OOM, HTTP/2 abuse, protobuf, unbounded allocation, rate limiting

2026-03-14
go-vuln-info-disclosure
信息安全分析师

Use when auditing Go code involving logging, error handling, HTTP response data, Kubernetes Secret management, or credential storage. Covers CWE-200/532/522/312/552. Keywords: information disclosure, credential leak, log exposure, Kubernetes Secret, json tag, struct formatting, error message, stack trace, Rancher, Argo CD, sensitive data

2026-03-14
go-vuln-injection
信息安全分析师

Use when auditing Go code involving OS command execution, SQL queries, template rendering, or child command invocation. Covers CWE-78/89/77/94/88. Keywords: command injection, SQL injection, exec.Command, os/exec, database/sql, text/template, html/template, argument injection, shell injection, Gogs, Grafana, MCP stdio

2026-03-14
go-vuln-path-traversal
信息安全分析师

Use when auditing Go code involving file path operations, archive extraction, symlink handling, container volume mounts, or HTTP file serving. Covers CWE-22/59. Keywords: path traversal, directory traversal, filepath.Join, symlink, archive extraction, zip slip, tar, volume mount, go-git, Helm chart, os.Open, filepath.Clean

2026-03-14
当前展示该仓库 Top 8 / 28 个已收集 skills。
#002
CHYing-agent
21 个 skills49044更新于 2026-04-25
占该创作者 41%
ai-security
信息安全分析师

Use when facing AI security challenges involving prompt injection, LLM jailbreaks, or AI agent exploitation

2026-04-25
binary
信息安全分析师

Use when facing binary exploitation (PWN) or reverse engineering challenges involving memory corruption, ROP chains, shellcode, binary analysis, decompilation, unpacking, or dynamic tracing

2026-04-25
cryptography
信息安全分析师

Use when facing cryptography challenges involving cipher analysis, key recovery, mathematical attacks, or protocol weaknesses

2026-04-25
file-transfer
软件开发工程师

Use when transferring files between remote environments and local Docker containers via litterbox.catbox.moe relay or base64 chunked fallback

2026-04-25
forensics-misc
信息安全分析师

Use when facing digital forensics or misc challenges involving disk images, memory dumps, network captures, steganography, file format analysis, encoding puzzles, sandbox escapes, or archive manipulation

2026-04-25
infra-exploit
信息安全分析师

Use when conducting penetration testing, post-exploitation, lateral movement, domain attacks, cloud exploitation (AWS/GCP/Azure), container escape, or Kubernetes cluster attacks

2026-04-25
stagnation-recovery
软件开发工程师

Use when stuck, looping on same approach, making no progress after multiple tool calls, or receiving a stagnation warning from the system. Also trigger when you catch yourself retrying the same command with minor variations, getting repeated Permission denied or timeout errors, or unable to advance past a specific step for 10+ tool calls.

2026-04-25
web-security
信息安全分析师

Use when facing web security challenges involving injection, authentication bypass, IDOR, access control, CSRF, HRS, server-side vulnerabilities, or web application exploitation

2026-04-25
当前展示该仓库 Top 8 / 21 个已收集 skills。
#003
init-skills
2 个 skills131更新于 2025-12-29
占该创作者 3.9%
已展示 3 / 3 个仓库
已展示全部仓库