zhaji2333

19 mods across 1 repository, 66 stars between them.

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security review skill for applications that use large language models, such as chatbots, copilots, agents, and retrieval-based knowledge systems.

66 9d ago F 150 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

An Android application security audit workflow for examining APK files, including preinstalled and system apps, for unsafe components and access paths.

66 9d ago C 232 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security testing method for web and service interfaces such as REST, GraphQL, gRPC, and WebSocket APIs. It checks how requests, permissions, documentation, older versions, gateways, and resource limits behave.

66 9d ago A 87 tokens original MIT

apk-reversing

04

zhaji2333/CkSKILLS

Skill Claude CodeCodex

An Android app analysis process that turns an APK—the installable file for an Android app—into readable code, resources, native libraries, and web assets. It also identifies app-protection shells and attempts to restore the hidden contents.

66 9d ago A 151 tokens original MIT

auth-access-control

05

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-testing skill for login systems, sessions, permissions, account recovery, tokens, and multi-tenant applications, where separate customers share one system.

66 9d ago A 125 tokens original MIT

business-logic-race

06

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security review method for business workflows such as payments, refunds, transfers, stock, coupons, and subscriptions. It maps allowed state changes and checks whether those rules can be bypassed or repeated.

66 9d ago A 94 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-testing guide for cloud infrastructure, containers, operations tools, software delivery systems, third-party integrations, and exposed configuration data.

66 9d ago C 111 tokens original MIT

deserialization-xxe

08

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security guide for finding unsafe deserialization, XML external entity (XXE), and prototype-pollution flaws in applications and data parsers.

66 9d ago C 78 tokens original MIT

file-handling

09

zhaji2333/CkSKILLS

Skill Claude CodeCodex

扩展名:.php5/.phtml/.phar/.htaccess/.user.ini 双扩展:shell.php.jpg / shell.jpg.php %00截断:shell.php%00.jpg 内容:GIF89a头、图片马.

66 9d ago C 111 tokens original MIT

injection-vulns

10

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A guide for testing injection flaws, where attacker-controlled input is interpreted as database queries, shell commands, templates, or expressions.

66 9d ago A 105 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-auditing skill for WeChat, Alipay, Douyin, and Baidu mini programs, including their cloud functions and cloud data services. It covers recovering package contents, finding interfaces and secrets, and checking login, payment, access-control, and rendering risks.

66 9d ago A 160 tokens original MIT

recon-js-analysis

12

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-analysis workflow for mapping a web application's assets and examining its JavaScript, mobile apps, and exposed interfaces.

66 9d ago A 100 tokens original MIT

report

13

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-reporting guide for turning a confirmed vulnerability into a submission-ready DOCX report for security response or bug-bounty platforms.

66 9d ago A 183 tokens original MIT

source-code-audit

14

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A source-code security auditing method written in Chinese. It traces data from where it enters an application through its processing steps to dangerous operations, across languages such as PHP, Java, Python, Node.js, and Go.

66 9d ago A 75 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security guide for testing server-side request forgery (SSRF), where a server can be tricked into requesting attacker-chosen URLs.

66 9d ago C 89 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-testing guide for examining how web application firewalls (WAFs) and request filters block potentially dangerous requests.

66 9d ago A 81 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A specialized skill for analyzing Windows program files such as EXE, DLL, and driver files, including .NET applications. It covers examining how a program works and looking for security weaknesses.

66 9d ago A 129 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security skill for finding web vulnerabilities in user input, browser code, cross-origin settings, and rendered AI or Markdown content. XSS means injected content runs as someone else’s browser code; CSRF tricks a browser into making an unwanted request.

66 9d ago A 191 tokens original MIT

CkSKILLS AGENTS.md

19

zhaji2333/CkSKILLS

Instructions file CodexOpenCode

A set of instructions for a security-testing agent focused on finding and documenting software vulnerabilities. It covers areas such as business logic, access control, APIs, mobile apps, and third-party dependencies, with an emphasis on authorized testing.

66 9d ago A 5,750 tokens original MIT