hilang
Community@langbyyi
写代码,也拆代码;研究安全,也制造点有趣的东西。
Agent Skills by hilang
Showing 50 vetted skills indexed across 1 GitHub repositories.
dependency-confusion
Detect dependency confusion vulnerabilities across npm, pip, RubyGems, Maven, Composer, and Docker.
prototype-pollution
Detect prototype pollution vulnerabilities in JavaScript stacks via injection probes.
unauthorized-access-common-services
Verify unauthorized access to exposed databases, caches, and admin panels.
api-sec
Triage API security testing across REST, GraphQL, SOAP, and WebSocket interfaces.
ssti-server-side-template-injection
Detect and exploit server-side template injection vulnerabilities across web applications.
ctf-forensics
Analyze disk images, memory dumps, and network captures to recover flags.
csv-formula-injection
Detect CSV and spreadsheet formula injection vulnerabilities in exported files.
websocket-security
Detect WebSocket security vulnerabilities including CSWSH, missing authentication, and message injection.
graphql-and-hidden-parameters
Identify GraphQL API vulnerabilities including hidden parameters and authorization gaps.
ldap-injection-testing
Detect, exploit, and remediate LDAP injection vulnerabilities in directory-integrated applications.
ctf-misc
Solve miscellaneous CTF challenges with decoding, sandbox escapes, and constraint solving.
burp-mcp-vuln-check
Verify web vulnerabilities via Burp MCP proxy history and HTTP replay.
ctf-reverse
Analyze CTF binaries with static and dynamic reverse engineering workflows.
nosql-injection
Detect and triage NoSQL injection vulnerabilities in MongoDB, CouchDB, and Elasticsearch applications.
clickjacking
Detect clickjacking vulnerabilities by validating framing headers and generating PoC exploits.
ctf-malware
Analyze obfuscated malware and decrypt C2 traffic for CTF challenges.
path-traversal-lfi
Detect and exploit path traversal and LFI vulnerabilities in web applications.
solve-challenge
Triage CTF challenge inputs and categorize them into standard types.
xlsx
Create, edit, analyze, and validate Excel spreadsheet files with pandas and openpyxl.
Extract text, merge documents, fill forms, and OCR scanned PDFs.
type-juggling
Identify PHP type juggling vulnerabilities and magic hash bypasses.
authbypass-authentication-flaws
Identify and exploit authentication bypass vulnerabilities across login, password reset, MFA, and session systems.
ctf-ai-ml
Generate adversarial examples and bypass LLM safety filters for CTF challenges.
ctf-pwn
Solve CTF binary exploitation challenges with pwntools, ROPgadget, and GDB-pwndbg.