reverse-skill-router
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR 绕过变体、2887 份
$ npx -y skills add zhaoxuya520/reverse-skill --skill src-hunter --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
/src-hunterContext preview
The summary Claude sees to decide when to auto-load this skill.
实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR 绕过变体、2887 份
name: src-hunter description: 实战 SRC / 众测 / Bug bounty 漏洞挖掘工作流 skill。包含:5 阶段方法论(intake → recon → enum → hunt → report)、19 个攻击类 playbook(SQLi/XSS/RCE/SSRF/IDOR/CSRF/Path Traversal/File Upload/SSTI/XXE/Race/HTTP Smuggling/OAuth/JWT/SAML/GraphQL/Mobile/LLM/DoS)、305 个结构化 payload、263 个 WAF/EDR 绕过变体、2887 份 HackerOne 真实 High/Critical 已披露案例、77,000+ WooYun 案例统计、国产 OA / 中间件指纹库、银行 / 电信行业垂直 playbook。当用户提到 "src 挖洞 / src 漏洞挖掘 / bug bounty / 众测 / hackerone / 漏洞赏金 / SRC / 任意 X 漏洞 / 渗透测试" 或问"如何挖某个目标 / 怎么测某个 API / 如何绕过 WAF" 时触发。 argument-hint: "<target-or-program-or-phase>" level: 2
1. `NOW`: 确认当前 case 的 `scope.md` 存在且 `auth.status=granted`。没有 scope → `case-init.ps1`,**禁止**自动 `-AuthGranted` 2. `NOW`: 读取 `../../field-journal/precedent-pentest.md` — 日常操作说明,不代替 scope 3. `NOW`: 确认当前任务是否命中本 skill 的适用范围 4. `NEXT`: 读取 `../../tool-index.md`,校验工具可用性和实际路径 5. `NEXT`: 缺工具时调用 bootstrap,不要猜路径 6. `ACT`: 进入工作流。默认只读 playbook 骨架;`payloader/`、`waf-bypass.md` 仅在 scope 已 granted 且用户明确要 payload 时打开 7. `MUST NOT` 把「2887 H1 报告」当成本仓已跟踪目录(`h1-reports/` 不在树里) 8. `MUST NOT` 因 payload corpus 触发杀毒告警而关闭防护;优先核对 Git blob/hash 与 `docs/SECURITY-REVIEW-2026-09-03.md`
实战 Security Response Center / 众测 / Bug bounty 挖洞 skill。把白盒方法论翻译为黑盒探测,叠加真实案例统计与 payload 库。
---
**关键词命中**:
**不应使用本 skill**:
---
输入:程序名 / SRC 入口 URL / 子域。
要做的事:
**优先级判断**(基于命中类型预估命中率,参考 `references/methodology/05-srctimebox-priority.md`):
→ 详见 [`references/methodology/00-index.md`](references/methodology/00-index.md)
不发包给目标的情报收集:
**资产枚举**:
按攻击类型走对应 playbook,**每个 playbook 都包含**:方法论 + 参数频率表 + 真实 H1 案例 + 结构化 payload + WAF 绕过变体。
**优先级路径**(按命中率 + 价值排序):
| Playbook | 入口提示 | 文件 | |---|---|---| | **未授权访问** | Actuator/Swagger/默认端口/弱密码 | `references/playbooks/unauth-access.md` | | **信息泄露** | .git/.svn/.env/heapdump/路径列举 | `references/playbooks/info-disclosure.md` | | **任意 X 越权** | 用户态 ID 可遍历/可修改 | `references/playbooks/arbitrary-x-authz.md` | | **业务逻辑** | 密码重置/支付/订单/验证码 | `references/playbooks/logic-flaws.md` | | **OAuth/SAML/JWT** | 认证流/redirect_uri/token | `references/playbooks/oauth-saml-jwt.md` | | **API REST** | BOLA/Mass Assignment/速率 | `references/playbooks/api-rest.md` | | **SQLi** | 任何用户输入进 DB | `references/playbooks/sqli.md` | | **RCE** | 反序列化/SSTI/XXE/原型链/框架 | `references/playbooks/rce.md` | | **SSRF** | URL 入参/缓存/Host 注入 | `references/playbooks/ssrf-cache-host.md` | | **路径遍历** | 文件路径入参/LFI/RFI | `references/playbooks/path-traversal.md` | | **文件上传** | 上传点 + 解析漏洞 | `references/playbooks/file-upload.md` | | **XSS** | 任何用户输入进 HTML/JS | `references/playbooks/xss.md` | | **HTTP 走私** | 反代 + Content-Length | `references/playbooks/http-smuggling.md` | | **GraphQL** | introspection/嵌套 | `references/playbooks/graphql.md` | | **竞态** | 并发请求 / TOCTOU | `references/playbooks/race-conditions.md` | | **DoS** | ReDoS / 资源不限速 / 算法爆炸 | `references/playbooks/dos.md` | | **移动端** | Android / iOS APK | `references/playbooks/mobile.md` | | **LLM Agent** | Prompt 注入 / 工具调用 | `references/playbooks/llm-prompt-injection.md` | | **内网后渗透** | 凭据 / 横向 / 域 | `references/playbooks/intranet-postexp.md` |
**通用方法论**(不分攻击类型):
| 文档 | 关键内容 | |---|---| | [`methodology/01-attack-priority.md`](references/methodology/01-attack-priority.md) | RCE>文件写>认证绕过>注入>信息泄露 价值排序 | | [`methodology/02-bypass-toolkit.md`](references/methodology/02-bypass-toolkit.md) | 通用绕过决策树 + 编码 / 混淆 / WAF | | [`methodology/03-evidence-discipline.md`](references/methodology/03-evidence-discipline.md) | 黑盒证据规则 + 反幻觉 + 合规 | | [`methodology/04-control-gap-hunting.md`](references/methodology/04-control-gap-hunting.md) | 9 类敏感操作 → 应有控制 → 探测缺失 | | [`methodology/05-srctimebox-priority.md`](references/methodology/05-srctimebox-priority.md) | 6h / 单日 / HVV / 月度 时间盒模板 |
**行业垂直 playbook**(资产相关时优先看):
| 行业 | 文档 | 何时用 | |---|---|---| | 银行 / 支付 / 金融 | [`industry/banking-finance.md`](references/industry/banking-finance.md) | 目标含支付 / 网银 / 第三方支付聚合 | | 电信 / ISP | [`industry/telecom-isp.md`](references/industry/telecom-isp.md) | 目标是运营商 / BOSS / 网管 / 物联网卡 |
**字典 / 凭据**:
| 文档 | 用途 | |---|---| | [`dictionaries/default-credentials-cn.md`](references/dictionaries/default-credentials-cn.md) | 致远 / 通达 / 万户 / 泛微 / 用友 / 金蝶 / 华为 / 中兴 / 海康等国产凭据 | | [`dictionaries/chinese-srcfingerprints.md`](references/dictionaries/chinese-srcfingerprints.md) | 国产 OA / 中间件指纹 + 高频参数 + 一键检测命令 |
→ 用模板 [`templates/report-submission.md`](references/templates/report-submission.
Reverse Engineering / Authorized Penetration Testing / Security Research Skill Router Pack AI-powered routing + On-demand toolchain bootstrapping + Self-evolving knowledge base Supports Claude Code, Kiro, Cursor, Cline, and other AI coding clients 逆向/渗透/安全技能路由包 - AI 自动路由 + 按需自举工具链 + 自动进化经验库 | 支持 Claude Code / Kiro / Cursor / Cline 等代码 AI 客户端
Repo: zhaoxuya520/reverse-skill
Use the reverse-skill repository from Codex for authorized reverse engineering, security…
Use for authorized security assessment of REST, GraphQL, WebSocket, or SOAP APIs, including…
在 CLI 环境下做 Android APK 逆向时使用。适用于 APK 解包、Java 反编译、smali 修改、重打包、Frida 动态 Hook,以及按需切换到 so/native…
Use for authorized multi-stage attack-path planning and orchestration when a task spans…
跨版本符号迁移与二进制差分。当你有旧版本的符号/逆向结果,需要快速迁移到新版本时使用。 适用场景:内核缺 PDB 用旧版符号推导、程序更新后批量迁移函数名、应用更新后快速定位新偏移。…
Use for authorized binary analysis in Binary Ninja, including HLIL/MLIL/LLIL inspection,…