do-whilefor
User面向授权安全测试、AI 辅助渗透测试与漏洞研究的可复用 Security Skills 。
Categories
Indexed Skills (5)
pentest-windftsy
A Web security assessment workflow built on globally installed Chrome DevTools MCP and Burp MCP. It establishes real browser state, synchronizes Burp evidence, models endpoints and permissions, validates vulnerabilities endpoint by endpoint, and completes threat convergence. It outputs structured data only.
security-hunt
Perform authorized, evidence-driven security testing across Web, APIs, identity, authorization, files, protocols, cryptography, native code, containers, and system boundaries. Use when the user supplies an authorized target, traffic, code, credentials, anomaly, or vulnerability-research goal and expects dynamic validation, impact verification, and evidence-based rating rather than a checklist or scanner summary.
pentest-lyan
Perform dynamic security validation on explicitly authorized web targets, covering authentication, authorization, object ownership, tenant isolation, state transitions, and business rules, and reach strict conclusions using reproducible evidence, verified impact, and structured state. Use when the user provides an authorized web target and asks for penetration testing, a vulnerability assessment, or validation of web security boundaries. Do not use for unauthorized targets, social engineering, mobile-only testing, infrastructure scanning, or general security advice without a concrete authorized web target.
web-vulnhunt
Authorized security testing methodology for web apps, APIs, multi-tenant SaaS, Spring Boot / Cloud Gateway stacks, FIDO/WebAuthn passwordless auth, mobile backends, and OAuth/SSO integrations. Use whenever the user asks to test, probe, scan, find vulnerabilities in, or pentest any web service — including bug bounty engagements, authorized pentests, CTF challenges, post-patch re-verification, CVSS scoring, subdomain/asset discovery, WAF/auth-filter bypass, **authorization bypass / IDOR / broken access control / missing @PreAuthorize / privilege escalation** testing, FIDO2/UAF testing, token-chain analysis, or writing vulnerability reports. Also triggers on the words "AcmeAuth", "Keycloak", "Okta", "PingFederate", "Auth0", or any passwordless-auth vendor. This is a defensive skill for authorized work only — always confirm scope before any active test.
tscanplus
Operates TscanPlus security scanner via MCP tools or CLI for authorized targets only. Use when the user mentions TscanPlus, port/URL/POC/subdomain scanning, MCP integration, ip_scan, tscan_scan, or recon on IPs, domains, or URLs in any AI assistant with MCP support.
Bio shown is the top-scored skill's repo description as a fallback — real GitHub bios land in a future update.