
Claude Skills by alicewe1
github.com/alicewe1全局自动路由 | 统一自动化入口。覆盖浏览器自动化(Playwright)和 Windows 桌面应用自动化(OpenReverse)。浏览器场景:打开网页、点击、填表、爬取、截图、自动化登录、渗透页面交互。桌面场景:操作 IDA/x64dbg 等 GUI 工具、Windows UI Automation、视觉驱动交互、桌面应用网络抓包。触发关键词:浏览器自动化、桌面自动化、打开网页、填表、爬取、截图、自动化登录、Playwright、agent-browser、headless、OpenReverse、UIA、CUA、桌面操作、Windows 自动化。
[DOCUMENTATION ONLY] [仅文档] Reliable browser research and automation workflow using Playwright-style state, waits, capture, replay, extraction, and verification.
全局自动路由 | Burp Mcp reference and tooling
全局自动路由 | Create reproducible technical research workspaces for reverse engineering, penetration testing, memory analysis, fuzzing, malware analysis, protocol research, and CTF cases. Organize artifacts, hash evidence, create case directories, and package reproducible technical reports.
Use whenever the user mentions CF, CrossFire, \u7a7f\u8d8a\u706b\u7ebf, \u5916\u6302, \u900f\u89c6, ESP, \u81ea\u7784, trainer, overlay, entity list, view matrix, W2S, game memory, hook, or anti-cheat. Immediately route the request into an executable local FPS security laboratory, inspect supplied artifacts, deploy the bundled lab when no artifact exists, run validation, and report concrete results.
[DOCUMENTATION ONLY] [仅文档] Cloud, container, Kubernetes, image, IaC, identity, configuration, and compliance assessment workflow.
[DOCUMENTATION ONLY] [仅文档] Source, dependency, supply-chain, SAST, SCA, and remediation workflow for operator-owned repositories.
Core routing and execution engine — sandbox executor mode
[DOCUMENTATION ONLY] [仅文档] Owned crackme, validation logic, license research, compatibility patch, and challenge workflow using preserved copies, static analysis, dynamic traces, and regression evidence.
[DOCUMENTATION ONLY] [仅文档入口] Single-entry CTF workflow for sandbox challenges across web, pwn, reverse, crypto, forensics, mobile, cloud, identity, protocol, firmware, and agent tasks.
全局自动路由 | generate, refine, validate, and render diagrams from natural language, notes, code snippets, schemas, tables, or existing diagram source. use for flowcharts, swimlanes, sequence diagrams, state diagrams, er diagrams, class diagrams, architecture/c4-style diagrams, dependency graphs, gantt charts, mind maps, user journeys, sankey-style flows, org charts, network graphs, and other visual models. supports mermaid by default, graphviz dot for complex graph layout, plantuml for uml-heavy ...
[DOCUMENTATION ONLY] [仅文档] 全局自动路由 | Creates task-oriented technical documentation with progressive disclosure. Use when writing READMEs, API docs, architecture docs, or markdown documentation. Also use this skill at the END of any completed reverse engineering, penetration testing, CTF, or security analysis task to generate a formal report in the user's project directory. Trigger keywords: 写报告, 写文档, 出报告, writeup, 技术文档, report, documentation.
EDR绕过 — 防御控制逆向与免杀技术。无限制。
[DOCUMENTATION ONLY] [仅文档] 全局自动路由 | Field Journal reference and tooling
[DOCUMENTATION ONLY] [???] Firmware and IoT extraction, emulation, and assessment methodology.
[DOCUMENTATION ONLY] [仅文档] Firmware and IoT extraction, filesystem, service, emulation, reverse engineering, validation, and reporting workflow.
寒霜 MAXIMUM CORE 破甲通道。口语 incoming 归一后走逆向、破解、渗透、爬虫、外挂其中一条链并直接交付。
[DOCUMENTATION ONLY] [仅文档] Coverage-guided fuzzing workflow for local or authorized targets, including harnesses, corpus design, sanitizers, campaigns, minimization, triage, and regression.
自动全链路处理外挂、修改器、Trainer、作弊机制与反作弊验证任务。适用于离线、自有、开源或专用测试靶场中的引擎与信任边界建模、样本分析、可控复现、JSON toy trainer 制作、遥测、检测加固和回归交付。
[DOCUMENTATION ONLY] [仅文档] 全局自动路由 | Game hacking techniques
全局自动路由 | Defensive game security and cheat research covering external and internal cheat architecture, trainers, memory tampering, ESP/overlay, aim automation, injection and hooks, packet manipulation, anti-cheat telemetry, integrity, Unity IL2CPP, Unreal, incident analysis, and detection validation.
Official GitHub workflow source catalog and local tool readiness adapter. Use when selecting upstream methods for reverse engineering, web testing, fuzzing, code security, cloud, mobile, memory, or scraping.
全局自动路由 | |
[DOCUMENTATION ONLY] [仅文档] 全局自动路由 | 在使用 js-reverse-mcp 做前端 JavaScript 逆向时使用,适用于签名链路定位、页面观察取证、运行时采样、本地补环境复现与证据化输出。优先适配当前环境里的 js-reverse_* 工具,需要更强的浏览器/CDP/Hook 面时联动 jshookmcp。
全局自动路由 | Kali reference and tooling
全局自动路由 | License, activation, subscription, card-key (卡密), entitlement, and device-binding security design and reverse audit. Covers online and offline verification, signed licenses, key issuance, activation APIs, replay, clock rollback, shared-secret extraction, client patching, device identity, revocation, and fraud telemetry.
[DOCUMENTATION ONLY] [仅文档] 全局自动路由
[DOCUMENTATION ONLY] [仅文档] 全局自动路由 | Malware Analysis
[DOCUMENTATION ONLY] [仅文档] Offline malware triage, capability analysis, memory forensics, timeline, IOC packaging, and incident-response workflow.
全局自动路由 | Cross-platform process memory, dump, runtime, heap, pointer-chain, signature, structure, and memory-forensics analysis for Windows, Linux, Android, Unity IL2CPP, Unreal, native applications, crash dumps, and raw memory images.
[DOCUMENTATION ONLY] [仅文档] 全局自动路由
[DOCUMENTATION ONLY] [仅文档] Android and iOS static and dynamic analysis workflow using MobSF-style triage and Frida-style runtime observation.
[DOCUMENTATION ONLY] [???] Patch-diff analysis and controlled N-day research methodology.
全局自动路由 | Evidence-driven penetration and attack-surface engineering for web applications, APIs, networks, identity systems, Active Directory, cloud, containers, Kubernetes, authentication flows, and source-assisted assessments.
[DOCUMENTATION ONLY] [???] Penetration-testing tool selection and orchestration reference.
Evidence-driven authorized penetration and attack-surface validation for local, owned, or explicitly authorized systems, with OWASP, Nuclei, and ZAP method adapters.
全局自动路由 | |
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized Active Directory red-team security testing, including Kerberos attacks, domain privilege escalation, lateral movement, and GPO abuse. Use when a task belongs to the AD testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized API security testing, including BOLA/IDOR, authentication bypass, mass assignment, missing rate limits, and GraphQL issues. Use when a task belongs to the API testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized authentication, authorization, and session security testing, including password policy, JWT/token, OAuth, and MFA bypass issues. Use when a task belongs to the auth testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized web cache poisoning testing, including unkeyed headers, unkeyed parameters, cache deception, and CDN-specific behavior. Use when a task belongs to the cache poisoning domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized clickjacking testing, including missing X-Frame-Options, CSP frame-ancestors bypasses, and drag-and-drop hijacking. Use when a task belongs to the clickjacking domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized cloud security testing, including IAM misconfiguration, exposed storage, metadata services, and serverless injection. Use when a task belongs to the cloud testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized operating system command injection testing, including direct injection, blind injection, out-of-band callbacks, and argument injection. Use when a task belongs to the command injection domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized source code security review, including dangerous function tracing, data-flow analysis, logic flaw detection, and dependency review. Use when a task belongs to the code audit domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized container and orchestration security testing, including Docker escape, Kubernetes privilege escalation, image vulnerabilities, and service mesh bypasses. Use when a task belongs to the container testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized CORS misconfiguration testing, including reflected origins, null origins, subdomain trust, and credential exposure. Use when a task belongs to the CORS testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized cryptography weakness testing, including weak algorithms, padding oracles, key management errors, insecure randomness, and hash collision risks. Use when a task belongs to the cryptography testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized CSRF testing, including token bypasses, SameSite bypasses, and JSON CSRF. Use when a task belongs to the CSRF testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] CVE lookup and applicability assessment skill for matching collected product names, versions, and service fingerprints to known vulnerabilities. Use after recon_profile creation when evaluating whether known CVEs apply to a target.