wgpsec/aboutsecurity
csrf-methodology
CSRF 跨站请求伪造检测与利用。当目标表单/API 缺少 CSRF Token、使用 Cookie 认证、有敏感操作(修改密码/转账/绑定邮箱)时使用。通过诱导受害者点击链接以其身份执行操作
Installation
npx skills add https://github.com/wgpsec/aboutsecurity
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
PluginEval quality methodology — dimensions, rubrics, statistical methods, and scoring formulas…
5.9K installsAudit websites and landing pages for conversion issues and design evidence-based A/B tests. Use…
4.9K installs>- Reconnaissance and methodology playbook. Use when mapping assets, discovering endpoints, fin…
3.2K installs>- Use after competitive-platform-analysis has produced a tiered competitor set. Scores each co…
2.9K installsSPARC (Specification, Pseudocode, Architecture, Refinement, Completion) comprehensive developme…
1.2K installsMaster the complete penetration testing lifecycle from reconnaissance through reporting. This s…
711 installsAlso in this package
Other skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
master
History
- First seen on skills.sh
- First recorded snapshot · 22 installs