ok-helloworld avatar

ok-helloworld

Community

@ok-helloworld

16Followers
|
2Public Repos
|
46Published Skills

念念不忘,必有回响

Agent Skills by ok-helloworld

Showing 46 vetted skills indexed across 1 GitHub repositories.

ok-helloworldok-helloworld
241

vibe-pentest

Automate black-box web penetration testing with multi-agent reconnaissance and evidence-based reporting.

Community
Advanced
ok-helloworldok-helloworld
241

file-access-vuln

Route file access and upload workflow testing to path traversal or processing-chain issues.

Community
Basic
ok-helloworldok-helloworld
241

injection-checking

Route suspected injection inputs to matching injection-testing workflows by sink context.

Community
Intermediate
ok-helloworldok-helloworld
241

prototype-pollution

Probe __proto__ and constructor.prototype paths to detect prototype pollution vulnerabilities.

Community
Advanced
ok-helloworldok-helloworld
241

saml-sso-assertion-attacks

Detect SAML SSO authentication bypass paths from assertion trust misconfigurations.

Community
Advanced
ok-helloworldok-helloworld
241

api-sec

Route API security testing to workflows based on observed target patterns.

Community
Basic
ok-helloworldok-helloworld
241

http-host-header-attacks

Identify Host header injection and routing abuse vectors in web applications.

Community
Advanced
ok-helloworldok-helloworld
241

websocket-security

Identify WebSocket handshake weaknesses, CSWSH conditions, and message-level vulnerabilities.

Community
Intermediate
ok-helloworldok-helloworld
241

graphql-and-hidden-parameters

Discover hidden GraphQL fields and authorization gaps via schema and type probing.

Community
Advanced
ok-helloworldok-helloworld
241

xxe-xml-external-entity

Detect and exploit XXE vulnerabilities for file disclosure and blind OOB exfiltration.

Community
Advanced
ok-helloworldok-helloworld
241

nosql-injection

Detect NoSQL injection via MongoDB operator manipulation and blind enumeration.

Community
Advanced
ok-helloworldok-helloworld
241

clickjacking

Assess X-Frame-Options and CSP frame-ancestors to detect clickjacking vulnerabilities.

Community
Intermediate
ok-helloworldok-helloworld
241

type-juggling

Probe PHP loose comparisons to verify authentication and signature bypasses.

Community
Advanced
ok-helloworldok-helloworld
241

authbypass-authentication-flaws

Identify authentication bypass risks across login, password reset, MFA, and session boundaries.

Community
Advanced
ok-helloworldok-helloworld
241

api-recon-and-docs

Discover reachable API endpoints, schemas, and versioned surfaces from REST, mobile, and GraphQL targets.

Community
Intermediate
ok-helloworldok-helloworld
241

sqli-sql-injection

Identify SQL injection vulnerabilities and generate DB-specific exploitation evidence.

Community
Advanced
ok-helloworldok-helloworld
241

business-logic-vuln

Detect business workflow abuse vulnerabilities across multi-step state-machine flows.

Community
Intermediate
ok-helloworldok-helloworld
241

ssrf-server-side-request-forgery

Detect and validate SSRF vulnerabilities in server-side URL fetch paths.

Community
Advanced
ok-helloworldok-helloworld
241

jndi-injection

Detect Java JNDI injection sinks and map feasible RMI, LDAP, or DNS vectors.

Community
Advanced
ok-helloworldok-helloworld
241

csrf-cross-site-request-forgery

Test state-changing endpoints for CSRF weaknesses and anti-CSRF controls.

Community
Advanced
ok-helloworldok-helloworld
241

xss-cross-site-scripting

Select context-appropriate XSS payloads for HTML, attribute, JavaScript, URL, and XML sinks.

Community
Advanced
ok-helloworldok-helloworld
241

upload-insecure-files

Validate file upload paths for bypass and processing-chain exploits.

Community
Advanced
ok-helloworldok-helloworld
241

web-cache-deception

Detect web cache deception and poisoning vulnerabilities across CDN intermediaries.

Community
Advanced
ok-helloworldok-helloworld
241

idor-broken-object-authorization

Detect IDOR and broken object level authorization across web and API requests.

Community
Advanced