.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/unclecheng-li/vulnclaw
home/skills/unclecheng-li/vulnclaw
unclecheng-li avatar

unclecheng-li/vulnclaw

50 skills

View on GitHub
$npx skills add unclecheng-li/vulnclaw
SkillInstalls
ai-mcp-securityAI与MCP安全评估 — Prompt注入、工具滥用、MCP信任边界、Agent权限逃逸、数据泄露、模型风险、GAARM风险矩阵—android-pentest安卓应用渗透测试 — APK分析、Hook、自动化测试、运行态驱动、签名恢复、抓包分析—client-reverse客户端逆向与Burp重放 — 复杂客户端签名恢复、加密还原、请求链追踪、稳定重放,适用于已授权安卓App渗透测试、浏览器JS签名、桌面客户端逆向—crypto-toolkit编码解码与加解密工具 — base64/URL/Hex/HTML实体编码解码,MD5/SHA哈希,AES/DES/RSA加解密,JWT解析,Caesar/ROT13密码,栅栏/Vigenere密码,Unicode转义,Morse电码等—ctf-cryptoCTF密码学攻击知识库 — RSA攻击(小指数/共模/Wiener/Coppersmith)、AES攻击(Padding Oracle/ECB字节翻转/GCM nonce重用)、ECC攻击、LFSR/LCG/PRNG攻击、古典密码、LWE格攻击—ctf-miscCTF杂项知识库 — Python Jail逃逸、Bash Jail逃逸、编码链识别与解码、QR/音频/图像隐写、游戏VM逆向、CTFd API导航、Linux提权—ctf-webCTF Web攻击知识库 — PHP弱比较绕过、命令注入空格绕过、eval回显技巧、SSTI注入链、反序列化利用链、PHP代码审计checklist、常见flag位置—cve-triageCVE lookup and triage — map discovered services/versions to known CVEs via the cve_lookup tool, score by CVSS/exploitability, and prioritize what to verify…—hackeroneHackerOne 赏金项目 scope-guard 流程 — 读取 program scope,强制 scope 与 program rules,再逐个把 in-scope asset 交给 pentest-flow—intranet-pentest-advanced内网渗透高级 — 横向移动、凭据窃取、提权、持久化、隧道代理、AD攻击、ADCS滥用、Exchange/SharePoint攻击—osint-reconOSINT 开源情报收集知识库 — 四维信息收集模型(服务器→网站→域名→人员),维度四(人员信息)条件触发—pentest-tools渗透工具速查 — 编码解码、反向Shell、红队工具、漏洞利用、密码攻击、内网工具、凭据窃取、提权、隧道代理、系统命令、信息收集、域渗透、Web工具、Windows工具—rapid-checklist渗透速查与Payload — 快速Payload家族、绕过提醒、验证顺序、常见测试卡片,适用于已知测试方向后快速查找—redteam-ad-detail-packDomain routing and boundary guidance for authorized Active Directory red-team security testing, including Kerberos attacks, domain privilege escalation,…—redteam-api-detail-packDomain routing and boundary guidance for authorized API security testing, including BOLA/IDOR, authentication bypass, mass assignment, missing rate limits, and…—redteam-auth-detail-packDomain routing and boundary guidance for authorized authentication, authorization, and session security testing, including password policy, JWT/token, OAuth,…—redteam-cache-poison-detail-packDomain routing and boundary guidance for authorized web cache poisoning testing, including unkeyed headers, unkeyed parameters, cache deception, and…—redteam-clickjacking-detail-packDomain routing and boundary guidance for authorized clickjacking testing, including missing X-Frame-Options, CSP frame-ancestors bypasses, and drag-and-drop…—redteam-cloud-detail-packDomain routing and boundary guidance for authorized cloud security testing, including IAM misconfiguration, exposed storage, metadata services, and serverless…—redteam-cmdi-detail-packredteam-code-audit-detail-packDomain routing and boundary guidance for authorized source code security review, including dangerous function tracing, data-flow analysis, logic flaw…—redteam-container-detail-packDomain routing and boundary guidance for authorized container and orchestration security testing, including Docker escape, Kubernetes privilege escalation,…—redteam-cors-miscfg-detail-packDomain routing and boundary guidance for authorized CORS misconfiguration testing, including reflected origins, null origins, subdomain trust, and credential…—redteam-crypto-detail-packDomain routing and boundary guidance for authorized cryptography weakness testing, including weak algorithms, padding oracles, key management errors, insecure…—redteam-csrf-detail-packDomain routing and boundary guidance for authorized CSRF testing, including token bypasses, SameSite bypasses, and JSON CSRF.—redteam-cve-lookupCVE lookup and applicability assessment domain card. Use after reconnaissance has identified products, versions, services, or fingerprints and red-team mode…—redteam-cve-validationCVE validation domain card. Use after CVE lookup has produced applicable or candidate CVEs and red-team mode needs scoped evidence to decide whether to…—redteam-deserialize-detail-packDomain routing and boundary guidance for authorized insecure deserialization testing, including Java, PHP, Python, .NET, and gadget-chain analysis.—redteam-evasion-detail-packDomain routing and boundary guidance for authorized defense evasion and bypass testing, including WAF bypass, AV/EDR evasion, logging considerations, and…—redteam-file-detail-packDomain routing and boundary guidance for authorized file operation vulnerability testing, including path traversal, arbitrary file read/write/upload, and…—redteam-injection-detail-packDomain routing and boundary guidance for authorized general injection testing outside SQL injection, including NoSQL, LDAP, XPath, and expression language…—redteam-logic-detail-packDomain routing and boundary guidance for authorized business logic vulnerability testing, including race conditions, flow bypass, price tampering, permission…—redteam-mobile-detail-packDomain routing and boundary guidance for authorized mobile application security testing, including insecure storage, certificate pinning bypass, exposed…—redteam-network-detail-packDomain routing and boundary guidance for authorized network-layer security testing, including exposed services, protocol downgrade, man-in-the-middle risks,…—redteam-open-redirect-detail-packDomain routing and boundary guidance for authorized open redirect testing, including parameter redirects, meta or JavaScript redirects, and OAuth redirect_uri…—redteam-payload-detail-packDomain routing and boundary guidance for authorized payload construction and weaponization analysis, including shellcode, file format payloads, phishing…—redteam-postex-detail-packDomain routing and boundary guidance for authorized post-exploitation testing after initial access, including privilege escalation, persistence, lateral…—redteam-recon-detail-packDomain routing and boundary guidance for authorized reconnaissance and information gathering, including subdomain enumeration, port scanning, directory…—redteam-recon-intakeRecon intake skill for first contact with a bare domain, URL, or IP address.—redteam-reverse-detail-packDomain routing and boundary guidance for authorized reverse engineering analysis, including decompilation, debugging, protocol reversing, firmware extraction,…—redteam-sqli-detail-packDomain routing and boundary guidance for authorized SQL injection testing, including union-based, blind, error-based, stacked query, and second-order SQL…—redteam-ssrf-detail-packDomain routing and boundary guidance for authorized SSRF testing, including basic SSRF, blind SSRF, protocol smuggling, and cloud metadata access paths.—redteam-ssti-detail-packDomain routing and boundary guidance for authorized server-side template injection testing, including Jinja2, Twig, Freemarker, Velocity, and Thymeleaf…—redteam-subdomain-takeover-detail-packDomain routing and boundary guidance for authorized subdomain takeover testing, including dangling CNAME records, NS takeover, and cloud service takeover paths…—redteam-web-detail-packRouting and boundary guidance for authorized general web application security testing.—redteam-xss-detail-packDomain routing and boundary guidance for authorized cross-site scripting testing, including reflected, stored, DOM-based, mXSS, and CSP bypass variants.—redteam-xxe-detail-packDomain routing and boundary guidance for authorized XXE testing, including file read, SSRF, blind XXE, and parameter entity variants.—secknowledge-skillWeb+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 150 风险 + OWASP Top 10 (LLM/ASI/WSTG)。 TRIGGER when 任务是实战安全测试:渗透测试、漏洞挖掘/利用、红队攻防、安全审计 (SAST/DAST)、…—web-pentestWeb应用渗透测试 — 针对Web应用的完整渗透流程,含技术栈识别、目录枚举、认证测试、输入验证、逻辑漏洞—web-security-advancedWeb高级安全测试 — 注入攻击族、协议安全、认证与逻辑漏洞、文件与部署安全、现代Web攻击面,含完整Playbook—