Skip to main content
Yliken
GitHub 创作者资料

Yliken

按仓库查看 1 个 GitHub 仓库中的 45 个已收集 skills。

已收集 skills
45
仓库
1
更新
2026年4月20日
仓库分布

Skills 分布在哪些仓库

按已收集 skill 数展示主要仓库,并显示它们在该创作者目录中的占比和职业覆盖。

仓库浏览

仓库与代表性 skills

api-auth-and-jwt-abuse
信息安全分析师

API authentication and JWT abuse playbook. Use when testing bearer tokens, API keys, claim trust, header spoofing, rate limits, and API auth boundary weaknesses.

2026年4月20日
api-authorization-and-bola
信息安全分析师

API authorization and BOLA testing playbook. Use when APIs expose object identifiers, nested resources, hidden writable fields, or weak function-level authorization.

2026年4月20日
api-recon-and-docs
信息安全分析师

API reconnaissance and documentation review playbook. Use when discovering endpoints, schemas, versions, OpenAPI specs, hidden docs, and surface area for API testing.

2026年4月20日
api-sec
信息安全分析师

Entry P1 category router for API security. Use when choosing between API recon, authorization, token abuse, and hidden-parameter workflows before any deeper API topic skill.

2026年4月20日
auth-sec
信息安全分析师

Entry P1 category router for authentication and authorization. Use when testing login flows, sessions, object authorization, JWT, OAuth, CORS, CSRF, and enterprise SSO weaknesses before any deeper auth topic skill.

2026年4月20日
authbypass-authentication-flaws
信息安全分析师

Authentication bypass testing playbook. Use when assessing login flows, password reset logic, account recovery, MFA bypass, token predictability, brute-force resistance, and session boundary flaws.

2026年4月20日
business-logic-vuln
信息安全分析师

Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than parser-level input injection.

2026年4月20日
business-logic-vulnerabilities
信息安全分析师

Business logic vulnerability playbook. Use when reasoning about workflows, race conditions, price manipulation, coupon abuse, state machines, and multi-step authorization gaps.

2026年4月20日
已展示 8 / 45 个已收集 Skill。
已展示 1 / 1 个仓库
已展示全部仓库