Summary
- Java 源码文件操作类漏洞审计。当在 Java 白盒审计中需要检测文件相关漏洞时触发。
- 覆盖 5 类文件风险: 任意文件上传(MultipartFile/Servlet Part/类型绕过)、任意文件读取(NIO/IO流/路径穿越)、
- 任意文件写入(覆盖配置/WebShell落地)、归档提取漏洞(ZipInputSt…
wgpsec/aboutsecurity
npx skills add https://github.com/wgpsec/aboutsecurity
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
>- Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege esc…
111K installsAudit a website's SEO with Firecrawl. Use when the user asks for an SEO audit, metadata and hea…
31.6K installsAudits Python + BigQuery pipelines for cost safety, idempotency, and production readiness. Retu…
8.8K installsSecurity audit of a codebase — web apps, APIs, services, CLI tools, libraries, daemons, and mor…
5.4K installsAnalyze a repository to generate recommended Claude Code settings.json permissions. Use when se…
3.9K installsOther skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
master