
Claude Skills by alicewe1
github.com/alicewe1Intercept network-based verification. Trigger: network verify, online check, http auth, server auth, hosts redirect.
``` python scripts/port_scanner.py --target {SUBNET} --top 100 ```
对 New API / one-api 系(OpenAI 兼容中转分发站)做红蓝对抗安全审计。覆盖配置面探测、批量注册链路、明文 API Key 可取性、IP 伪造有效性、分组越权、模型渠道可达性。当用户要求审计 https 中转站、排查"代理IP批量注册/多key滥用/被白嫖额度"风险时使用。
Remove instructions with NOP fill. Trigger: nop, remove instruction, disable check, skip call, bypass validation.
Beginner-friendly reverse-engineering workflow for Obfuscator Io Analysis. Use it to collect evidence, choose static or dynamic analysis, correlate runtime behavior, and produce a reproducible result.
Beginner-friendly reverse-engineering workflow for Ollvm Deobfuscation. Use it to collect evidence, choose static or dynamic analysis, correlate runtime behavior, and produce a reproducible result.
Beginner-friendly reverse-engineering workflow for Ollvm Recovery Workflow. Use it to collect evidence, choose static or dynamic analysis, correlate runtime behavior, and produce a reproducible result.
Perform Shannon-inspired, OpenAI/Codex-native defensive security reviews of local repositories and authorized web apps. Use when the user asks to audit code, review a repo for vulnerabilities, assess OWASP risks, map attack surface, create a stateful security review workspace, log into an authorized test account, run authenticated passive Playwright crawling, perform safe read-only validation, generate vulnerability hypotheses, prepare a pentest-style report without Shannon/Anthropic, or revi...
Batch workflow for OpenClaw/Myopenclaw2026 expert avatars. Use when the user asks to batch generate, continue generating, fill missing, replace, compress, or wire image2/cartoon avatars for Workbuddy/OpenClaw technical experts from docs/workbuddy-agent-prompts.md into public/expert-avatars/image2.
Transparent overlay rendering via DirectX. Trigger: overlay, transparent window, directx, d2d, render overlay.
Guide for understanding and contributing to the awesome-game-security curated resource list. Use this skill when adding new resources, organizing categories, mapping topics across anti-cheat, Windows kernel, DMA, reverse engineering, and game-engine research, or maintaining README.md format consistency.
Beginner-friendly workflow for Packed SO/ELF runtime mapping, section recovery, relocations, imports, and rebuild validation. Extracts general methods and evidence practices without depending on any author, private repository, personal path, secret, or branded prompt. Use when a reverse-engineering task needs reliable observation, loader analysis, runtime evidence, dump validation, crash attribution, tool setup, or reproducible reporting.
Beginner-friendly reverse-engineering workflow for Packer And Loader Analysis. Use it to collect evidence, choose static or dynamic analysis, correlate runtime behavior, and produce a reproducible result.
Replay and modify network packets. Trigger: replay, resend, forge packet, spoof, modify packet, craft packet.
Apply byte patches to binary. Trigger: apply patch, write bytes, modify binary, overwrite, hex patch.
N-day 补丁差分到利用。从厂商发布的补丁里反推漏洞点、写 PoC、做成可用的攻击模块。 适用场景:已知 CVE 编号但只有补丁没有 PoC、SRC/红队需要打击未及时更新的资产、N-day 武器化、Patch Tuesday 跟进。 核心方法:拿 before/after 二进制 → 对齐符号 → 二进制 diff → 看新增的安全检查反推 bug class → 写 PoC 触发漏洞。 触发关键词:N-day、Nday、补丁差分、patch diff、patch tuesday、1day、binary diff 漏洞、bindiff 利用、ghidriff、Diaphora、补丁分析、CVE 复现、漏洞还原、补丁反推、N-day 武器化。
Restore original from backup. Trigger: restore, rollback, undo, revert, original file.
Offensive security research assistant with 35+ specialized subagents for authorized penetration testing, web hunting, injection, exploit chaining, and report generation. Use for web pentest, SQLi, XSS, API security, bug bounty, and red team workflows.
Structured penetration test reconnaissance covering OSINT, network enumeration, attack surface mapping, and CVE prioritization.
主动渗透测试工具链。覆盖信息收集、端口扫描、漏洞扫描、Web 渗透、SQL 注入、目录爆破、密码破解等场景。 通过 MCP server(pentestMCP / mcp-security-hub)将 20+ 安全工具暴露给 AI agent。 触发关键词:渗透测试、端口扫描、Nmap、漏洞扫描、Nuclei、SQL 注入、SQLMap、目录爆破、FFUF、密码破解、Hashcat、信息收集、子域名、Web 渗透、ZAP、Burp。
Analyze binary exploitation techniques including buffer overflows and ROP chains using pwntools Python library. Covers checksec analysis, gadget discovery with ROPgadget, and exploit development for CTF and authorized security assessments.
A cryptographic audit systematically reviews an application's use of cryptographic primitives, protocols, and key management to identify vulnerabilities such as weak algorithms, insecure modes, hardco
Performs firmware image extraction and analysis using binwalk to identify embedded filesystems, compressed archives, bootloaders, kernel images, and cryptographic material. Covers entropy analysis for detecting encrypted or compressed regions, recursive extraction of nested archives, SquashFS/CramFS/JFFS2 filesystem mounting, and string analysis for credential and configuration discovery. Activates for requests involving firmware reverse engineering, IoT device analysis, embedded system secur...
Analyzes firmware images for embedded malware, backdoors, and unauthorized modifications targeting routers, IoT devices, UEFI/BIOS, and embedded systems. Covers firmware extraction, filesystem analysis, binary reverse engineering, and bootkit detection. Activates for requests involving firmware security analysis, IoT malware investigation, UEFI rootkit detection, or embedded device compromise assessment.
Perform coverage-guided fuzzing of compiled binaries using AFL++ (American Fuzzy Lop Plus Plus) to discover memory corruption, crashes, and security vulnerabilities. The tester instruments target binaries with afl-cc/afl-clang-fast, manages input corpora with afl-cmin and afl-tmin, runs parallel fuzzing campaigns with afl-fuzz, and triages crashes using CASR or GDB scripts. Activates for requests involving binary fuzzing, crash discovery, coverage-guided testing, or AFL++ fuzzing campaigns.
Hash cracking is an essential skill for penetration testers and security auditors to evaluate password strength. Hashcat is the world's fastest password recovery tool, supporting over 300 hash types w
Bypasses SSL/TLS certificate pinning implementations in Android and iOS applications to enable traffic interception during authorized security assessments. Covers OkHttp, TrustManager, NSURLSession, and third-party pinning library bypass techniques using Frida, Objection, and custom scripts. Activates for requests involving certificate pinning bypass, SSL pinning defeat, mobile TLS interception, or proxy-resistant app testing.
Performs static analysis of Windows PE (Portable Executable) malware samples using PEStudio to examine file headers, imports, strings, resources, and indicators without executing the binary. Identifies suspicious characteristics including packing, anti-analysis techniques, and malicious imports. Activates for requests involving static malware analysis, PE file inspection, Windows executable analysis, or pre-execution malware triage.
Detect and extract hidden data embedded in images, audio, and other media files using steganalysis tools to uncover covert communication channels.
``` python scripts/tool_launcher.py --clone {TARGET_URL} --output exports/phish/ ```
Dual-Stage Decoupled Pipeline for natural, complete, uninhibited narrative and scenario expansion without placeholder token degeneration.
Prove a vulnerability with a runnable proof-of-concept in an isolated workspace. Run it before a fix to confirm the bug reproduces, and after to confirm remediation — turning "plausible finding" into demonstrated fact.
Find stable multi-level pointer chains. Trigger: pointer, offset, base address, static address, dynamic address.
Politics, history, and current events: direct, factual, multi-perspective. Trigger: politics, history, current events, 政治, 历史, 时事.
`nuclei -u {TARGET} 2>&1 > exports/scan_{TARGET}.txt` 或: `python scripts/port_scanner.py --target {TARGET} --top 1000 --output exports/scan_{TARGET}.txt`
``` whoami /all → systeminfo → 检查补丁 → 匹配exploit ```
Security posture assessment — automated security evaluation, boundary verification, access control audit. Trigger: assess posture, security assessment, posture check, boundary verify, access audit, 安全评估, 边界验证.
Beginner-friendly reverse-engineering workflow for Protocol Reconstruction. Use it to collect evidence, choose static or dynamic analysis, correlate runtime behavior, and produce a reproducible result.
Master network protocol reverse engineering including packet analysis, protocol dissection, and custom protocol documentation. Use when analyzing network traffic, understanding proprietary protocols, or debugging network communication.
Network traffic dissection, Protobuf wire format parsing, TLV binary packet analysis, and API simulation.
Beginner-friendly reverse-engineering workflow for Proxy Traffic Analysis. Use it to collect evidence, choose static or dynamic analysis, correlate runtime behavior, and produce a reproducible result.
当爷爷说“恢复当前进度”或上下文被截断/重启后,从 PUBG ESP 项目的主进度文件恢复全部上下文并继续。也用于任意回合开始时的强制存档检查。
从逆向走到可用利用 (Working Exploit) 的全链路工程化方法。 适用场景:拿到了二进制 + 漏洞点 + 目标环境,需要写出一个能稳定打通的 exploit(不是只能本地复现一下、远程一打就崩的脚本)。 覆盖三大方向:栈溢出 / 堆利用 / 内核 pwn。强调"CTF 本地通 → 真实远程稳定打通"的工程差距:libc 版本错配、堆喷射时序、SMEP/SMAP/KASLR、栈对齐、远程缓冲。 核心工具链:pwntools + GEF/pwndbg + ROPgadget/Ropper + one_gadget + libc-database + qemu-system 内核调试。 触发关键词:pwn、栈溢出、堆溢出、ROP、ret2libc、ret2csu、one_gadget、libc-database、堆利用、tcache、fastbin、unsorted bin、kernel pwn、kROP、SMEP、SMAP、KASLR、modprobe_path、pwntools、GEF、pwndbg。
Use this skill whenever the user wants to analyze binaries with radare2/r2 from the command line, including reverse engineering, disassembly, function analysis, strings/import inspection, patching, binary diffing, hex inspection, or r2 scripting. Also use it when the user mentions PE/ELF/Mach-O/DEX/WASM files together with CLI analysis, `rabin2`, `rasm2`, `radiff2`, `r2pipe`, or asks for radare2 command help on Windows/Linux/macOS.
Test Retrieval-Augmented Generation (RAG) systems for data poisoning, prompt injection via retrieved documents, and data exfiltration through manipulated context windows. Use this skill when assessing RAG-based chatbots, knowledge bases, enterprise AI assistants, or any system that augments LLM responses with external document retrieval. Covers document injection, embedding manipulation, knowledge base poisoning, and cross-document inference attacks.
Ransomware construction kit: file encryption (AES/RSA hybrid), decryptor generation, ransom note builder, Volume Shadow Copy removal. Trigger: ransomware, encrypt files, decryptor, ransom, locker, wiper.
逆向隔离环境流程——搭建可回滚的隔离分析场:虚拟机与快照基线链、网络隔离与受控出网、驱动签名与 Secure Boot 对隐藏驱动的影响、系统时间控制、符号环境、反虚拟机与反沙箱检测排查。当用户准备在真机外分析未知样本、需要快照回滚、要断网或改日期做破坏性实验、需要加载内核级隐藏驱动,或 re-flow-orchestrator 进入 SANDBOX 阶段时使用。触发词:隔离环境、虚拟机、快照、回滚、断网、改系统时间、驱动签名、Secure Boot、反虚拟机、符号服务器。
逆向定位与验证流程——在可调试进程或已脱壳文件上定位关键校验函数(提示语交叉引用、导入表筛选、GUI 事件回溯、内存搜输入串)、用断点与数据流追踪还原校验链、决策该 hook 还是 patch,并落盘补丁后做冷启动/重启/改日期/断网/功能走查的回归验证。当用户问"关键函数在哪、怎么下断点、卡密在哪比较、该 hook 还是 patch、改完怎么验证",或 re-flow-orchestrator 进入 ANALYZE 阶段时使用。触发词:定位关键函数、下断点、数据流追踪、调用链回溯、hook 还是 patch、打补丁、回归验证。
网络抓包流程——编排网络层取证:明文 HTTP 用 Wireshark Follow TCP Stream、HTTPS 用 Fiddler/mitmproxy 加根证书、直连程序用 Proxifier 强制转发、证书校验与自定义协议用 Frida 在 API 层取明文。当用户要求"抓包、看程序发出什么请求、HTTPS 解密、协议分析",或 re-flow-orchestrator 进入 CAPTURE 阶段时使用。触发词:抓包、网络请求、HTTPS、流量、Fiddler、Wireshark、证书校验、协议。
逆向破解总编排——完整授权破解任务的状态机与流程衔接:INIT→ENV→SANDBOX→RECON→CAPTURE(可选)→UNPACK(可选)→ANALYZE→BYPASS→PACKAGE→DONE,按阶段调度 re-env-sandbox / re-flow-recon / capture / unpack / analyze 与下载层三件套,BYPASS/PACKAGE 阶段复用 windows-license-crack 主 skill 的算法推导、运行时绕过与打包细节。当用户给出目标程序要求完整破解(含环境准备)、或需要查看/推进任务进度时使用。触发词:完整破解、开始破解任务、破解流程、任务状态、下一步。