zhaji2333/CkSKILLS

基于 Claude Code / Codex 的 SRC 漏洞挖掘 Agent 技能体系 —— 系统级提示词 + 14 个专项安全测试 Skill 知识库

73Stars on the repository
21Mods indexed here, across every type
4d agoLast push, which is what freshness is scored on
MITLicence, which decides whether bodies are shown

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security review skill for applications that use large language models, such as chatbots, copilots, agents, and retrieval-based knowledge systems.

not rated 73 4d ago F 150 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

An Android application security audit workflow for examining APK files, including preinstalled and system apps, for unsafe components and access paths.

not rated 73 4d ago C 232 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security testing method for web and service interfaces such as REST, GraphQL, gRPC, and WebSocket APIs. It checks how requests, permissions, documentation, older versions, gateways, and resource limits behave.

not rated 73 changed today A 87 tokens original MIT

apk-reversing

04

zhaji2333/CkSKILLS

Skill Claude CodeCodex

An Android app analysis process that turns an APK—the installable file for an Android app—into readable code, resources, native libraries, and web assets. It also identifies app-protection shells and attempts to restore the hidden contents.

not rated 73 4d ago A 151 tokens original MIT

auth-access-control

05

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-testing skill for login systems, sessions, permissions, account recovery, tokens, and multi-tenant applications, where separate customers share one system.

not rated 73 changed today A 125 tokens original MIT

business-logic-race

06

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security review method for business workflows such as payments, refunds, transfers, stock, coupons, and subscriptions. It maps allowed state changes and checks whether those rules can be bypassed or repeated.

not rated 73 4d ago A 94 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-testing guide for cloud infrastructure, containers, operations tools, software delivery systems, third-party integrations, and exposed configuration data.

not rated 73 4d ago C 111 tokens original MIT

deserialization-xxe

08

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security guide for finding unsafe deserialization, XML external entity (XXE), and prototype-pollution flaws in applications and data parsers.

not rated 73 4d ago C 78 tokens original MIT

file-handling

09

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-testing guide for file uploads, downloads, previews, imports, archives, and other features that read or write files.

not rated 73 4d ago C 111 tokens original MIT

injection-vulns

10

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A guide for testing injection flaws, where attacker-controlled input is interpreted as database queries, shell commands, templates, or expressions.

not rated 73 4d ago A 105 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-auditing skill for WeChat, Alipay, Douyin, and Baidu mini programs, including their cloud functions and cloud data services. It covers recovering package contents, finding interfaces and secrets, and checking login, payment, access-control, and rendering risks.

not rated 73 4d ago A 160 tokens original MIT

recon-js-analysis

12

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-analysis workflow for mapping a web application's assets and examining its JavaScript, mobile apps, and exposed interfaces.

not rated 73 changed today A 100 tokens original MIT

report

13

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-reporting guide for turning a confirmed vulnerability into a submission-ready DOCX report for security response or bug-bounty platforms.

not rated 73 changed today A 0 tokens original MIT

source-code-audit

14

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A source-code security auditing method written in Chinese. It traces data from where it enters an application through its processing steps to dangerous operations, across languages such as PHP, Java, Python, Node.js, and Go.

not rated 73 4d ago A 75 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security guide for testing server-side request forgery (SSRF), where a server can be tricked into requesting attacker-chosen URLs.

not rated 73 4d ago C 89 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security-testing guide for examining how web application firewalls (WAFs) and request filters block potentially dangerous requests.

not rated 73 4d ago A 81 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A specialized skill for analyzing Windows program files such as EXE, DLL, and driver files, including .NET applications. It covers examining how a program works and looking for security weaknesses.

not rated 73 4d ago A 129 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security skill for finding web vulnerabilities in user input, browser code, cross-origin settings, and rendered AI or Markdown content. XSS means injected content runs as someone else’s browser code; CSRF tricks a browser into making an unwanted request.

not rated 73 4d ago A 191 tokens original MIT

hunt-clueboard

19

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A Markdown clue board for preserving research findings, leads, assumptions, and disproven evidence across coding-agent sessions.

not rated 73 4d ago A 103 tokens original MIT

zhaji2333/CkSKILLS

Skill Claude CodeCodex

A security investigation method for finding publicly reachable paths and keys when the normal website code does not reveal them. It also checks whether apparent encryption is really access control.

not rated 73 4d ago A 150 tokens original MIT

At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: