wgpsec/aboutsecurity

race-condition-methodology

条件竞争/并发漏洞的检测与利用。当目标有余额/积分/优惠券消费、文件上传后检查删除、一次性 token 验证、限购/限量操作时使用。通过并发请求在校验与执行之间的时间窗口进行利用(TOCTOU)。CTF 中常见的重复领奖、余额竞态题型

First seen Mar 25, 2026

Installation

$ npx skills add https://github.com/wgpsec/aboutsecurity

Summary

条件竞争/并发漏洞的检测与利用。当目标有余额/积分/优惠券消费、文件上传后检查删除、一次性 token 验证、限购/限量操作时使用。通过并发请求在校验与执行之间的时间窗口进行利用(TOCTOU)。CTF 中常见的重复领奖、余额竞态题型

Similar popular skills

Related neighbors and high-traction skills in the same topics — useful to compare before installing.

Also in this package

Other skills from wgpsec/aboutsecurity · top by installs.

npx skills add https://github.com/wgpsec/aboutsecurity

Browse all from wgpsec/aboutsecurity

More details

Agent compatibility

Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.

Claude Code Not declared
Cursor Not declared
Codex Not declared
GitHub Copilot Not declared
Windsurf Not declared
Gemini CLI Not declared
Cline Not declared
OpenCode Not declared

Repository health

Stars 1.7K
Default branch master
Open issues 0
Status Active

History

  1. First seen on skills.sh
  2. First recorded snapshot · 4 installs