
Claude Skills by alicewe1
github.com/alicewe1[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized insecure deserialization testing, including Java, PHP, Python, .NET, and gadget-chain analysis. Use when a task belongs to the deserialization testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Governance skill for red-team mode phase selection, router selection, detailed pack selection, OPSEC-aware progression, and choosing the next concrete skill. Use when red-team mode needs command-level decision support before technical testing.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized defense evasion and bypass testing, including WAF bypass, AV/EDR evasion, logging considerations, and traffic obfuscation. Use when a task belongs to the evasion domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized file operation vulnerability testing, including path traversal, arbitrary file read/write/upload, and LFI/RFI. Use when a task belongs to the file vulnerability domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized general injection testing outside SQL injection, including NoSQL, LDAP, XPath, and expression language injection. Use when a task belongs to the general injection domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized business logic vulnerability testing, including race conditions, flow bypass, price tampering, permission logic errors, and bulk operation abuse. Use when a task belongs to the logic testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized mobile application security testing, including insecure storage, certificate pinning bypass, exposed components, and binary reverse engineering. Use when a task belongs to the mobile testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized network-layer security testing, including exposed services, protocol downgrade, man-in-the-middle risks, and segmentation bypasses. Use when a task belongs to the network testing domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized open redirect testing, including parameter redirects, meta or JavaScript redirects, and OAuth redirect_uri abuse. Use when a task belongs to the open redirect domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized payload construction and weaponization analysis, including shellcode, file format payloads, phishing payloads, and staged or stageless payload choices. Use when a task belongs to the payload construction domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized post-exploitation testing after initial access, including privilege escalation, persistence, lateral movement, data collection, and cleanup considerations. Use when a task belongs to the post-exploitation domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized reconnaissance and information gathering, including subdomain enumeration, port scanning, directory discovery, fingerprinting, and OSINT. Use when a task belongs to the recon domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Recon intake skill for first contact with a bare domain, URL, or IP address. Use to build an initial recon_profile and provide factual inputs for CVE lookup and attack-path routing.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized reverse engineering analysis, including decompilation, debugging, protocol reversing, firmware extraction, and deobfuscation. Use when a task belongs to the reverse engineering domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized SQL injection testing, including union-based, blind, error-based, stacked query, and second-order SQL injection variants. Use when a task belongs to the SQL injection domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized SSRF testing, including basic SSRF, blind SSRF, protocol smuggling, and cloud metadata access paths. Use when a task belongs to the SSRF domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized server-side template injection testing, including Jinja2, Twig, Freemarker, Velocity, and Thymeleaf engines. Use when a task belongs to the SSTI domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized subdomain takeover testing, including dangling CNAME records, NS takeover, and cloud service takeover paths such as S3, Azure, and Heroku. Use when a task belongs to the subdomain takeover domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Routing and boundary guidance for authorized general web application security testing. Use as a web testing router when the attack surface should be dispatched to more specific web vulnerability skills.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized cross-site scripting testing, including reflected, stored, DOM-based, mXSS, and CSP bypass variants. Use when a task belongs to the XSS domain and needs scope, evidence, pivot, or exit criteria.
[DOCUMENTATION ONLY] [仅文档] Domain routing and boundary guidance for authorized XXE testing, including file read, SSRF, blind XXE, and parameter entity variants. Use when a task belongs to the XXE domain and needs scope, evidence, pivot, or exit criteria.
全局自动路由 | Deep reverse engineering for PE, ELF, Mach-O, firmware, drivers, APK/DEX, .NET, Go, Rust, Unity IL2CPP, Unreal, packed binaries, custom VMs, and undocumented protocols. Use when Codex receives a binary, disassembly, pseudocode, crash, native library, game artifact, firmware image, obfuscated application, or needs IDA/Ghidra/Frida/angr/Unicorn automation, algorithm recovery, unpacking, patching, or protocol reconstruction.
[DOCUMENTATION ONLY] [仅文档] 全局自动路由 | Provides reverse engineering techniques. Use when the main job is to understand how a compiled, obfuscated, packed, or virtualized target works before exploiting or solving it, including binaries, APKs, WASM, firmware, custom VMs, bytecode, malware-like loaders, and anti-debug or anti-analysis logic. Do not use it when the vulnerability is already understood and the remaining task is exploitation; use pwn instead. Do not use it for pure web workflows, log o...
Deep, evidence-driven reverse engineering workflow for PE, ELF, Mach-O, firmware, drivers, bytecode, protocols, and local binaries.
原创外部依赖桥接:把 Open ReverseLab(LING71671/open-reverselab,GPL-3.0)作为可选外部工具链接入本包,不捆绑其任何内容。路由、安装、配置与退出条件都在本文件内,反向/CTF/APK/PE 任务命中时按需接入。
Open-source reverse engineering lab: 197-article knowledge base, 43 MCP tools, 5-board signal routing, CTF/APK/PE automation toolchain, and full attack-network graph routing. Automatically route matching reverse, CTF, binary, APK, PE, malware, web-security, game-security, and security-research tasks here without an activation phrase.
Unified structured web collection workflow using request-first Scrapy-style crawling and Playwright-style browser fallback, with schema, retry, deduplication, and quality gates.
[DOCUMENTATION ONLY] [仅文档] Software implementation, debugging, refactoring, testing, and delivery workflow. Automatically route matching coding tasks here without requiring an activation phrase.
[DOCUMENTATION ONLY] [仅文档] Supply-chain assurance workflow for sequential eni-solo execution.
[DOCUMENTATION ONLY] [仅文档] 全局自动路由
Deterministic eni-solo router. Use at the start of every substantive prompt to select exactly one workflow, print its stages, and load one primary Skill.
Default sandbox executor workflow
Offline Windows PE packing, unpacking triage, and evidence-backed reverse-engineering workflow. Use when the user says "寒霜" and asks to inspect a local EXE/DLL, identify packers or protectors, triage UPX/PyInstaller/.NET/native/VM-protected binaries, audit local reverse tools, create a copy-only analysis case, decompile or dynamically observe a local binary, or verify whether an authorization state is real, persistent, and cross-machine.
Enumerate game entity objects. Trigger: entity list, player list, actor list, object enumeration.
ESP-based original entry point location. Trigger: esp law, pushad, popad, entry point, oep, original entry.
Defense evasion: AMSI bypass, ETW patch, obfuscation, packing, code signing bypass. Trigger: evade, obfuscate, pack, amsi, etw, bypass defender, hide, encode payload, crypt.
Scan process memory for known values. Trigger: scan, search value, find address, exact value, gold, health, ammo.
Redirect execution to custom code. Trigger: hook, detour, redirect execution, intercept, trampoline.
Exploit development: shellcode generation, ROP chain building, format string attacks, buffer overflow patterns. Trigger: exploit dev, shellcode, rop, buffer overflow, format string, use-after-free, heap spray, ret2libc.
Backup before modification. Trigger: backup, copy, save original, .bak, snapshot.
Financial system research: money movement, laundering, shell companies, mixing, structuring, tax evasion, bank fraud. Trigger: laundering, shell company, mixing, structuring, tax evasion, bank fraud, 洗钱, 资金, 壳公司, 混币.
固件 / IoT 渗透链。从拿到一坨 .bin / .img 开始,闭环走完逆向 → 提取 → 模拟 → 利用。 方法论遵循 OWASP FSTM 九阶段;工具链以 binwalk v3、unblob、EMBA、Firmadyne、AFL++ 为主。 适用场景:路由器/摄像头/智能家居固件审计、固件升级包逆向、IoT CVE 复现、嵌入式 0day 挖掘。 触发关键词:固件、firmware、IoT、binwalk、unblob、UART、JTAG、squashfs、UBI、JFFS2、Firmadyne、QEMU 全系统仿真、EMBA、固件渗透、路由器固件、嵌入式漏洞利用、bootloader、NVRAM、FAT、firmware analysis toolkit。
Structured web application penetration testing with OWASP methodology, curated payload references, 6-gate validation, and professional report generation
Hook network functions with Frida. Trigger: frida, hook send, hook recv, intercept traffic, capture packets.
Complete cracking workflow. Trigger: full crack, complete crack, crack workflow, 完整破解.
Complete game enhancement chain. Trigger: full game, complete cheat, game workflow, 完整外挂.
不输出聊天内容。每阶段静默执行,写结果到exports/。 Phase 1: `python scripts/port_scanner.py --target {TARGET} --top 1000 --output exports/01_recon_{TARGET}.txt` Phase 2: `python Skills/dns-enum/scripts/dns_enum.py --target {TARGET} --subdomains --output exports/02_dns_{TARGET}.txt` Phase 3: `python Skills/web-scan/scripts/web_scanner.py --target {TARGET} --dirs --output exports/03_web_{TARGET}.txt` Phase 4: `python Skills/vuln-scan/scripts/vuln_scanner.py --target {TARGET} --versions --output exports/04_vuln_{TAR...
Complete reverse engineering chain. Trigger: full reverse, complete analysis, reverse workflow, 完整逆向.
Complete unpacking chain. Trigger: full unpack, complete unpack, unpack workflow, 完整脱壳.
Decompile and identify key functions. Trigger: function, decompile, pseudocode, routine, subroutine.