wgpsec/aboutsecurity

elasticsearch-attack

Elasticsearch 未授权访问与利用。当发现目标开放 9200/9300 端口、Elasticsearch 服务无认证、需要从 ES 获取索引数据或实现远程命令执行时使用。覆盖未授权访问、认证绕过、索引数据窃取、MVEL/Groovy 脚本…

First seen May 2, 2026

Installation

$ npx skills add https://github.com/wgpsec/aboutsecurity

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from wgpsec/aboutsecurity · top by installs.

npx skills add https://github.com/wgpsec/aboutsecurity

Browse all from wgpsec/aboutsecurity

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 1.7K
Default branch master
Open issues 0
Status Active

History

  1. First seen on skills.sh
  2. First recorded snapshot · 15 installs