do-whilefor
User面向授权安全测试、AI 辅助渗透测试与漏洞研究的可复用 Security Skills 集合。
Categories
Indexed Skills (3)
security-hunt
Perform authorized, evidence-driven security testing across Web, APIs, identity, authorization, files, protocols, cryptography, native code, containers, and system boundaries. Use when the user supplies an authorized target, traffic, code, credentials, anomaly, or vulnerability-research goal and expects dynamic validation, impact verification, and evidence-based rating rather than a checklist or scanner summary.
pentest-lyan
对用户明确授权的 Web 目标执行动态安全验证,覆盖认证、授权、对象归属、租户隔离、状态流转和业务规则, 并用可复现证据、影响验证和结构化状态得出严格结论。 Use when the user provides an authorized web target and asks for penetration testing, a vulnerability assessment, or validation of web security boundaries. Do not use for unauthorized targets, social engineering, mobile-only testing, infrastructure scanning, or general security advice without a concrete authorized web target.
tscanplus
Operates TscanPlus security scanner via MCP tools or CLI for authorized targets only. Use when the user mentions TscanPlus, port/URL/POC/subdomain scanning, MCP integration, ip_scan, tscan_scan, or recon on IPs, domains, or URLs in any AI assistant with MCP support.
Bio shown is the top-scored skill's repo description as a fallback — real GitHub bios land in a future update.