CtrlK
BlogDocsLog inGet started
Tessl Logo

Web 安全漏洞学习指南

OWASP 十大漏洞原理、影响与修复方案,覆盖 Python/Java 场景

Invalid
This skill can't be scored yet
Validation errors are blocking scoring. Review and fix them to unlock Quality, Impact and Security scores. See what needs fixing →
SKILL.md
Quality
Evals
Security

Web 安全漏洞学习指南

⚠️ 核心规则

  1. 永不信任用户输入 - 所有外部数据必须校验、转义、参数化
  2. 最小权限原则 - 仅授予完成任务所需的最小权限
  3. 纵深防御 - 多层安全措施,不依赖单一防护

十大漏洞速查

漏洞危害核心防御
🔴 注入RCE/数据泄露参数化查询
🔴 XSS会话劫持转义输出
🔴 认证缺陷账户接管强Token+限速
🔴 敏感数据泄露隐私泄露加密+脱敏
🔴 访问控制缺失越权操作后端鉴权
🟡 安全配置错误信息泄露关闭Debug
🟡 CSRF伪造操作Token验证
🟡 反序列化RCE禁用危险接口
🟡 SSRF内网探测白名单URL
⚪ 日志不足无法溯源完整审计

📦 按需加载资源

漏洞类型URI
注入漏洞skill://web-security-guide/references/injection.md
XSS攻击skill://web-security-guide/references/xss.md
认证会话skill://web-security-guide/references/auth-session.md
数据泄露skill://web-security-guide/references/data-exposure.md
访问控制skill://web-security-guide/references/access-control.md
配置错误skill://web-security-guide/references/security-config.md
CSRFskill://web-security-guide/references/csrf.md
反序列化skill://web-security-guide/references/deserialization.md
SSRFskill://web-security-guide/references/ssrf.md
日志监控skill://web-security-guide/references/logging-monitoring.md

💡 先用速查表定位问题,再按需加载详细文档


📦 可用资源

  • skill://web-security-guide/references/access-control.md
  • skill://web-security-guide/references/auth-session.md
  • skill://web-security-guide/references/csrf.md
  • skill://web-security-guide/references/data-exposure.md
  • skill://web-security-guide/references/deserialization.md
  • skill://web-security-guide/references/injection.md
  • skill://web-security-guide/references/logging-monitoring.md
  • skill://web-security-guide/references/security-config.md
  • skill://web-security-guide/references/ssrf.md
  • skill://web-security-guide/references/xss.md

根据 SKILL.md 中的 IF-THEN 规则判断是否需要加载

Repository
TencentBlueKing/bk-bcs
Last updated
Created

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.