Summary
CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖…
wgpsec/aboutsecurity
npx skills add https://github.com/wgpsec/aboutsecurity
CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖…
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
Analyze Azure resource groups and generate detailed Mermaid architecture diagrams showing the r…
566.5K installsList, find, and show Azure resources across subscriptions or resource groups. Handles prompts l…
566.5K installsAnalyze Azure resource groups and generate detailed Mermaid architecture diagrams showing the r…
8.9K installsAnalyze Azure resource health, diagnose issues from logs and telemetry, and create a remediatio…
8.7K installsCreate and troubleshoot AWS Glue connections to JDBC databases (Oracle, SQL Server, PostgreSQL,…
5.2K installsManages connected MCP sources for enterprise search. Detects available sources, guides users to…
4.8K installsOther skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
master