Summary
- Java 白盒审计漏洞利用链组装。当需要将 Java 审计中发现的多个漏洞组合为完整攻击路径、
- 或需要评估 Maven/Gradle 依赖中的已知 CVE 对项目的实际影响时触发。
- 核心: 单个中低危漏洞通过组合可升级为高危/Critical 利用链。
- 覆盖: 信息泄露→认证绕过→RCE 的典型链路、Gadget…
wgpsec/aboutsecurity
npx skills add https://github.com/wgpsec/aboutsecurity
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
>- Heap exploitation playbook. Use when targeting ptmalloc2/glibc heap vulnerabilities includin…
3K installs>- Linux kernel exploitation playbook. Use when exploiting kernel vulnerabilities (UAF, OOB, ra…
2.9K installs>- Browser and V8 exploitation playbook. Use when exploiting JavaScript engine vulnerabilities …
2.9K installs>- Format string exploitation playbook. Use when printf-family functions receive user-controlle…
3K installsN-day 补丁差分到利用。从厂商发布的补丁里反推漏洞点、写 PoC、做成可用的攻击模块。 适用场景:已知…
14 installsIdentifies and exploits SQL injection vulnerabilities in web applications during authorized pen…
430 installsOther skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
master