Skip to content
Security
Skill

/src-hunter

实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR 绕过变体、2887 份

BOOST
From plugin
reverse-skill
39k46 skills
Install
$ npx -y skills add zhaoxuya520/reverse-skill --skill src-hunter --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/src-hunter

Context preview

The summary Claude sees to decide when to auto-load this skill.

实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR 绕过变体、2887 份

SKILL.md

src-hunter.SKILL.md
name: src-hunter
description: 实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR 绕过变体、2887 份 HackerOne 真实 High/Critical 已披露案例、77,000+ WooYun 案例统计、国产 OA / 中间件指纹库、银行 / 电信行业垂直 playbook。当用户提到 "src 挖洞 / src 漏洞挖掘 / bug bounty / 众测 / hackerone / 漏洞赏金 / SRC / 任意 X 漏洞 / 渗透测试" 或问"如何挖某个目标 / 怎么测某个 API / 如何绕过 WAF" 时触发。
argument-hint: "<target-or-program-or-phase>"
level: 2

ACTION REQUIRED(读完后立刻执行)

1. `NOW`: 确认当前 case 的 `scope.md` 存在且 `auth.status=granted`。没有 scope → `case-init.ps1`,**禁止**自动 `-AuthGranted` 2. `NOW`: 读取 `../../field-journal/precedent-pentest.md` — 日常操作说明,不代替 scope 3. `NOW`: 确认当前任务是否命中本 skill 的适用范围 4. `NEXT`: 读取 `../../tool-index.md`,校验工具可用性和实际路径 5. `NEXT`: 缺工具时调用 bootstrap,不要猜路径 6. `ACT`: 进入工作流。默认只读 playbook 骨架;`payloader/`、`waf-bypass.md` 仅在 scope 已 granted 且用户明确要 payload 时打开 7. `MUST NOT` 把「2887 H1 报告」当成本仓已跟踪目录(`h1-reports/` 不在树里) 8. `MUST NOT` 因 payload corpus 触发杀毒告警而关闭防护;优先核对 Git blob/hash 与 `docs/SECURITY-REVIEW-2026-09-03.md`

SRC Hunter — 实战漏洞挖掘工作流

实战 Security Response Center / 众测 / Bug bounty 挖洞 skill。把白盒方法论翻译为黑盒探测,叠加真实案例统计与 payload 库。

---

何时使用本 skill

**关键词命中**:

  • "src 挖洞" / "src 漏洞" / "src 测试" / "Security Response Center"
  • "bug bounty" / "漏洞赏金" / "众测"
  • "hackerone" / "h1" / "bugcrowd" / "intigriti" / "yeswehack"
  • "如何挖 / 怎么测 / 怎么打 + 某目标 / 某接口 / 某参数"
  • "WAF 绕过" / "绕过 WAF" / "WAF bypass"
  • "任意账号 / 任意修改 / 任意删除 / 任意操作" 类越权
  • "密码重置" / "找回密码" 类逻辑
  • "未授权访问" / "默认凭据" / "Actuator" / "Spring 暴露" / "Redis 未授权"
  • 用户给一个 URL 或 API endpoint 让你测

**不应使用本 skill**:

  • 纯白盒源码审计(用 `code-audit` skill)
  • 已知漏洞的修复 / 防御问答(用通用对话)
  • 单独的 CTF 题目(这是真实环境工作流)

---

工作流 — 5 阶段

Phase 1 · Intake(接单)

输入:程序名 / SRC 入口 URL / 子域。

要做的事:

  • 抓 Scope(in-scope domains / IPs / mobile apps / API endpoints)
  • 抓 Out-of-scope(禁测内容、第三方服务、cloud assets exclusions)
  • 抓规则(payout tiers、disclosure window、retest policy、safe-harbor)
  • 抓测试账号 / 测试 header(如 `X-Bug-Bounty: <handle>`)

**优先级判断**(基于命中类型预估命中率,参考 `references/methodology/05-srctimebox-priority.md`):

  • 6 小时窗口 → 跑高命中率类型(密码重置 88% / 任意账号 86.4% / 提现 83.1%)
  • 单日窗口 → 加上信息泄露 + 资产暴露 + Actuator
  • HVV / 重点期 → 全谱

→ 详见 [`references/methodology/00-index.md`](references/methodology/00-index.md)

Phase 2 · Recon(被动侦察)

不发包给目标的情报收集:

  • **CT 日志**:crt.sh / Censys(找子域)
  • **历史快照**:Wayback / CommonCrawl
  • **GitHub 搜索**:`org:target` + 关键词(password / api_key / SECRET)
  • **搜索引擎 dorks**:`site:target.com inurl:/admin`、`filetype:env`、`intitle:Index of`
  • **ASN / IP 段**:bgp.he.net 找 IP 块
  • **Favicon hash**:FOFA / Shodan 找同 favicon 资产
  • **DNS 历史**:SecurityTrails / Whoisxmlapi

Phase 3 · Enum(主动探测)

**资产枚举**:

  • 子域:amass / subfinder / puredns / dnsx
  • 存活:httpx / naabu
  • 截图:gowitness / aquatone
  • 内容发现:ffuf / feroxbuster / dirsearch
  • 技术指纹:wappalyzer / webanalyze(同时查 `references/dictionaries/chinese-srcfingerprints.md` 命中国产组件)
  • JS 提取:linkfinder / subjs / gau / katana
  • 子域接管指纹:subjack / subzy

Phase 4 · Hunt(漏洞探测)

按攻击类型走对应 playbook,**每个 playbook 都包含**:方法论 + 参数频率表 + 真实 H1 案例 + 结构化 payload + WAF 绕过变体。

**优先级路径**(按命中率 + 价值排序):

| Playbook | 入口提示 | 文件 | |---|---|---| | **未授权访问** | Actuator/Swagger/默认端口/弱密码 | `references/playbooks/unauth-access.md` | | **信息泄露** | .git/.svn/.env/heapdump/路径列举 | `references/playbooks/info-disclosure.md` | | **任意 X 越权** | 用户态 ID 可遍历/可修改 | `references/playbooks/arbitrary-x-authz.md` | | **业务逻辑** | 密码重置/支付/订单/验证码 | `references/playbooks/logic-flaws.md` | | **OAuth/SAML/JWT** | 认证流/redirect_uri/token | `references/playbooks/oauth-saml-jwt.md` | | **API REST** | BOLA/Mass Assignment/速率 | `references/playbooks/api-rest.md` | | **SQLi** | 任何用户输入进 DB | `references/playbooks/sqli.md` | | **RCE** | 反序列化/SSTI/XXE/原型链/框架 | `references/playbooks/rce.md` | | **SSRF** | URL 入参/缓存/Host 注入 | `references/playbooks/ssrf-cache-host.md` | | **路径遍历** | 文件路径入参/LFI/RFI | `references/playbooks/path-traversal.md` | | **文件上传** | 上传点 + 解析漏洞 | `references/playbooks/file-upload.md` | | **XSS** | 任何用户输入进 HTML/JS | `references/playbooks/xss.md` | | **HTTP 走私** | 反代 + Content-Length | `references/playbooks/http-smuggling.md` | | **GraphQL** | introspection/嵌套 | `references/playbooks/graphql.md` | | **竞态** | 并发请求 / TOCTOU | `references/playbooks/race-conditions.md` | | **DoS** | ReDoS / 资源不限速 / 算法爆炸 | `references/playbooks/dos.md` | | **移动端** | Android / iOS APK | `references/playbooks/mobile.md` | | **LLM Agent** | Prompt 注入 / 工具调用 | `references/playbooks/llm-prompt-injection.md` | | **内网后渗透** | 凭据 / 横向 / 域 | `references/playbooks/intranet-postexp.md` |

**通用方法论**(不分攻击类型):

| 文档 | 关键内容 | |---|---| | [`methodology/01-attack-priority.md`](references/methodology/01-attack-priority.md) | RCE>文件写>认证绕过>注入>信息泄露 价值排序 | | [`methodology/02-bypass-toolkit.md`](references/methodology/02-bypass-toolkit.md) | 通用绕过决策树 + 编码 / 混淆 / WAF | | [`methodology/03-evidence-discipline.md`](references/methodology/03-evidence-discipline.md) | 黑盒证据规则 + 反幻觉 + 合规 | | [`methodology/04-control-gap-hunting.md`](references/methodology/04-control-gap-hunting.md) | 9 类敏感操作 → 应有控制 → 探测缺失 | | [`methodology/05-srctimebox-priority.md`](references/methodology/05-srctimebox-priority.md) | 6h / 单日 / HVV / 月度 时间盒模板 |

**行业垂直 playbook**(资产相关时优先看):

| 行业 | 文档 | 何时用 | |---|---|---| | 银行 / 支付 / 金融 | [`industry/banking-finance.md`](references/industry/banking-finance.md) | 目标含支付 / 网银 / 第三方支付聚合 | | 电信 / ISP | [`industry/telecom-isp.md`](references/industry/telecom-isp.md) | 目标是运营商 / BOSS / 网管 / 物联网卡 |

**字典 / 凭据**:

| 文档 | 用途 | |---|---| | [`dictionaries/default-credentials-cn.md`](references/dictionaries/default-credentials-cn.md) | 致远 / 通达 / 万户 / 泛微 / 用友 / 金蝶 / 华为 / 中兴 / 海康等国产凭据 | | [`dictionaries/chinese-srcfingerprints.md`](references/dictionaries/chinese-srcfingerprints.md) | 国产 OA / 中间件指纹 + 高频参数 + 一键检测命令 |

Phase 5 · Report(提交)

→ 用模板 [`templates/report-submission.md`](references/templates/report-submission.

Read more
Ships withreverse-skill

Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端

Get the whole plugin
Stats
39,460
Stars
5,492
Forks
Active
Maintenance
PowerShell
Language
MIT
License
11d ago
Last commit
4mo ago
Created
3h ago
Added

Repo: zhaoxuya520/reverse-skill

Other skills on reverse-skill.

binary-diff
Skill

binary-diff

跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…