Agent Skills by 公明
Showing 31 vetted skills indexed across 1 GitHub repositories.
attack-surface-recon
Maps target attack surfaces using passive and active reconnaissance tools and fingerprinting techniques.
source-code-hunting
Hunt source code leaks, hardcoded secrets, and supply-chain risks using grep, semgrep, and trufflehog.
blockchain-contract-attack
Guides auditing of smart contracts and DeFi protocols for reentrancy, access control, oracle, and flash loan vulnerabilities.
pentest-verification
Enforces evidence-based verification rules for recording penetration testing findings.
component-vuln-intel
Collects CVE, PoC, and exploit intelligence for identified components from public sources.
cyberstrike-eino-demo
Validates skill package loading, resource paths, and retrieval across HTTP APIs and Eino agents.
pentest-output-standards
Standardizes penetration testing reports, change ledgers, and negative-result documentation in Chinese.
pentest-blackboard
Records penetration testing facts, vulnerabilities, and attack-chain relationships in a SQLite project blackboard.
find-skills
Searches and installs agent skills from the open skills ecosystem using the Skills CLI.
csrf-testing
Detect, exploit, and mitigate Cross-Site Request Forgery vulnerabilities.
network-penetration-testing
Execute network penetration testing phases with Nmap, Nessus, and Metasploit.
xss-testing
Test web applications for reflected, stored, and DOM-based XSS vulnerabilities.
incident-response
Guide cybersecurity incident response through preparation, containment, and recovery phases.
deserialization-testing
Detect and exploit deserialization vulnerabilities in Java, PHP, and Python applications.
container-security-testing
Scan Docker images and audit Kubernetes configurations for security vulnerabilities.
ldap-injection-testing
Detect, exploit, and mitigate LDAP injection vulnerabilities in applications.
security-awareness-training
Create security awareness training programs covering password management and phishing detection.
vulnerability-assessment
Assess system and application vulnerabilities with CVSS risk scoring.
security-automation
Automate vulnerability scanning and security testing in CI/CD pipelines.
api-security-testing
Test REST API endpoints for common vulnerabilities like SQL injection and broken access control.
xxe-testing
Detect, exploit, and mitigate XML External Entity injection vulnerabilities.
idor-testing
Detect, exploit, and prevent IDOR vulnerabilities in web applications.
sql-injection-testing
Identify SQL injection vulnerabilities in web applications using sqlmap and manual testing.
file-upload-testing
Test file upload endpoints for unverified file types and validation bypasses.