wgpsec/aboutsecurity
ssti-methodology
服务端模板注入(SSTI)的检测、引擎识别和利用。当目标是Flask/Jinja2/Django/Twig/Mako/Pug应用、存在用户输入回显、参数名含template/name/message/greeting时使用。Phase…
Installation
npx skills add https://github.com/wgpsec/aboutsecurity
Similar popular skills
Related neighbors and high-traction skills in the same topics — useful to compare before installing.
PluginEval quality methodology — dimensions, rubrics, statistical methods, and scoring formulas…
5.9K installsAudit websites and landing pages for conversion issues and design evidence-based A/B tests. Use…
4.9K installs>- Reconnaissance and methodology playbook. Use when mapping assets, discovering endpoints, fin…
3.2K installs>- Use after competitive-platform-analysis has produced a tiered competitor set. Scores each co…
2.9K installsSPARC (Specification, Pseudocode, Architecture, Refinement, Completion) comprehensive developme…
1.2K installsMaster the complete penetration testing lifecycle from reconnaissance through reporting. This s…
711 installsAlso in this package
Other skills from wgpsec/aboutsecurity · top by installs.
npx skills add https://github.com/wgpsec/aboutsecurity
More details
Agent compatibility
Declared targets from SKILL.md / docs. Unmarked agents are not listed — the skill may still install via the CLI.
Repository health
master
History
- First seen on skills.sh
- First recorded snapshot · 21 installs