github.com/zhaoxuya520/reverse-skill
| Skill | Added | Review |
|---|---|---|
reverse-skill-router skills/SKILL.md Routes reverse engineering, exploitation, penetration testing, malware, mobile, firmware, browser automation, documentation, and security tasks to the appropriate specialist skill. Use when a task spans modules or the correct reverse-skill entrypoint is unclear. | 60 60 Impact — No eval scenarios have been run Securityby — The risk profile of this skill Version: 7e2097f | |
reverse-skill-router plugins/reverse-skill/skills/reverse-skill-router/SKILL.md Use the reverse-skill repository from Codex for authorized reverse engineering, security analysis, CTF, and defensive testing tasks. Requires the reverse-skill repository to be available as the current workspace or an explicitly supplied local path. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 7e2097f | |
src-hunter skills/pentest-tools/src-hunter/SKILL.md 实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR 绕过变体、2887 份 HackerOne 真实 High/Critical 已披露案例、77,000+ WooYun 案例统计、国产 OA / 中间件指纹库、银行 / 电信行业垂直 playbook。当用户提到 "src 挖洞 / src 漏洞挖掘 / bug bounty / 众测 / hackerone / 漏洞赏金 / SRC / 任意 X 漏洞 / 渗透测试" 或问"如何挖某个目标 / 怎么测某个 API / 如何绕过 WAF" 时触发。 | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 7e2097f | |
supply-chain-security skills/supply-chain-security/SKILL.md Use for software supply-chain security assessment covering SBOM, SCA, CI/CD pipelines, container images, build integrity, dependency provenance, and vulnerability reachability. | 64 64 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 7e2097f | |
thick-client skills/thick-client/SKILL.md Use for authorized security testing of desktop thick clients including local storage, update channels, IPC, traffic, and client-side trust boundaries. | 64 64 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 7e2097f | |
threat-hunting skills/threat-hunting/SKILL.md Use for blue-team threat hunting, detection engineering with Sigma/YARA, SIEM query design, and incident detection validation. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 7e2097f | |
threat-intelligence skills/threat-intelligence/SKILL.md Use for authorized OSINT and cyber threat intelligence that enriches IOCs, campaigns, impersonation, scams, or threat actors from public sources. Includes bounded X/Twitter search through Xquik, source preservation, corroboration, and evidence handoff. | 64 64 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 7e2097f | |
wifi-wireless skills/wifi-wireless/SKILL.md Use for authorized wireless security assessment including Wi-Fi capture, WPA handshake analysis, rogue AP detection research, and lab-only deauth testing. | 64 64 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 7e2097f | |
windows-ad skills/windows-ad/SKILL.md Use for authorized Active Directory and Windows identity attacks including Kerberos, AD CS, BloodHound paths, NTLM relay, and domain privilege escalation research. | 64 64 Impact — No eval scenarios have been run Securityby Critical Do not install without reviewing Version: 7e2097f |