灵感菇

AI 技能的自然生态,你的一句话,蔓延出无限连接。

搜索结果

全部能力

找到 1168 个相关结果 / 认证与权限

软件工程 / 诊断修复

idor-broken-object-authorization

idor-broken-object-authorization

515

IDOR and broken object authorization testing playbook. Use when requests expose object identifiers, tenant boundaries, writable fields, or missing object-level authorization checks.

Stars 634
testingauthapiidor

软件工程 / 诊断修复

API安全

api-sec

513

API 安全的 P1 分类入口路由。用于在任何更深层的 API 主题技能之前,在 API 侦察、授权、令牌滥用和隐藏参数工作流之间进行选择。

Stars 0
backendtestingsecurityauth

软件工程 / 诊断修复

csrf-cross-site-request-forgery

csrf-cross-site-request-forgery

513

CSRF testing playbook. Use when reviewing state-changing web flows, anti-CSRF defenses, SameSite behavior, JSON CSRF, login CSRF, and OAuth state handling.

Stars 634
testingauthcsrfcross

软件工程 / 诊断修复

paid-ads

paid-ads

512

You are an expert performance marketer with direct access to ad platform accounts. Your goal is to help create, optimize, and scale paid advertising campaigns…

Stars 37,694
uiperformancetestingpaid

软件工程 / 诊断修复

prompt-engineering

prompt-engineering

511

Expert guide on prompt engineering patterns, best practices, and optimization techniques. Use when user wants to improve prompts, learn prompting strategies,…

Stars 27,327
designuiperformancetesting

软件工程 / 诊断修复

cypress-author

cypress-author

511

创建、更新和修复 Cypress 测试(E2E/端到端测试和组件测试)。当用户要求创建测试、添加测试、编写测试、更新测试等时使用。

Stars 0
uitestingauthprompt

软件工程 / 诊断修复

oauth-oidc-misconfiguration

oauth-oidc-misconfiguration

508

OAuth and OIDC misconfiguration testing playbook. Use when reviewing redirect URI handling, state and nonce validation, PKCE, token audience, callback binding, and identity-provider trust flaws.

Stars 636
testingauthgithuboauth

软件工程 / 诊断修复

business-logic-vuln

business-logic-vuln

508

Entry P1 category router for business logic testing. Use when workflow abuse, race conditions, pricing flaws, or multi-step state attacks matter more than parser-level input injection.

Stars 633
testingauthapiworkflow

软件工程 / 诊断修复

playwright-local

playwright-local

508

Build browser automation and web scraping with Playwright on your local machine. Prevents 10 documented errors including CI timeout hangs, extension testing failures, and Ubuntu compatibility issues. Includes stealth mode for anti-bot bypass, authenticated sessions, infinite scroll handling, screenshot/PDF generation, and v1.57 Speedboard performance analysis. Use when: automating browsers, scraping protected sites, testing with real IPs, bypassing bot detection, generating screenshots/PDFs, or troubleshooting "target closed", "page.pause() hangs CI", "permission prompts block tests", or "Ubuntu 25.10 installation" errors.

Stars 783
uiperformancetestingplaywright

软件工程 / 诊断修复

cors-cross-origin-misconfiguration

cors-cross-origin-misconfiguration

507

CORS misconfiguration testing playbook. Use when analyzing cross-origin trust, credentialed browser reads, origin reflection, preflight policy bugs, and browser-based access to authenticated APIs.

Stars 633
testingsecurityauthapi

软件工程 / 诊断修复

agent-ui

agent-ui

507

Batteries-included agent component for React/Next.js from ui.inference.sh. One component with runtime, tools, streaming, approvals, and widgets built in.…

Stars 438
reactnextjsuiagent

软件工程 / 诊断修复

API认证与JWT滥用

api-auth-and-jwt-abuse

505

API 认证与 JWT 滥用手册。用于测试 Bearer Token、API 密钥、声明信任、请求头伪造、速率限制以及 API 认证边界弱点。

Stars 0
uitestingauthapi

软件工程 / 诊断修复

race-condition

race-condition

504

Race condition and TOCTOU testing for web apps. Use when testing one-time operations, concurrent HTTP abuse, rate-limit bypass, Turbo Intruder gates, HTTP/2 single-packet attacks, and CWE-362-style synchronization gaps.

Stars 636
uitestingauthapi

软件工程 / 诊断修复

authjs-skills

authjs-skills

499

Auth.js v5 setup for Next.js authentication including Google OAuth, credentials provider, environment configuration, and core API integration

Stars 20
nextjsuiauthapi

软件工程 / 诊断修复

安卓渗透测试技巧

android-pentesting-tricks

499

Android渗透测试手册。用于在授权移动安全评估期间测试Android应用的SSL pinning绕过、导出组件滥用、WebView漏洞、intent重定向、root检测绕过、tapjacking和备份提取。

Stars 0
backendtestingsecurityauth

软件工程 / 诊断修复

graphql-and-hidden-parameters

graphql-and-hidden-parameters

499

GraphQL and hidden parameter testing playbook. Use when exploring introspection, batching, undocumented fields, hidden parameters, schema abuse, and GraphQL authorization gaps.

Stars 634
testingauthgraphqland

软件工程 / 诊断修复

saml-sso-assertion-attacks

saml-sso-assertion-attacks

498

SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.

Stars 636
testingragsamlsso

软件工程 / 诊断修复

insecure-source-code-management

insecure-source-code-management

497

Source control and artifact exposure (.git, .svn, .hg, backups, .env). Use when recon finds VCS paths, 403 on hidden dirs, or backup/config leaks during authorized testing.

Stars 634
uitestingauthworkflow

软件工程 / 诊断修复

aicoin-freqtrade

aicoin-freqtrade

496

在用户使用 Freqtrade 时调用 — 策略创建、回测、超参数优化、切换策略/交易对/模拟模式、查询实盘机器人状态/余额/…

Stars 0
authapiagentaicoin

软件工程 / 部署发布

dependency-confusion

dependency-confusion

492

Supply-chain testing via package-manager dependency confusion: when internal package names resolve to attacker-controlled public registries, leading to malicious install and script execution. Use for npm/pip/gem/Maven/Composer/Docker manifest review and authorized red-team supply-chain exercises.

Stars 634
uitestingdockerauth

25 / 59