技能雷达 · GITHUB
值得安装的 Agent Skills。
汇总公开仓库中已验证的 Skills。安装前先看清它能做什么、包内包含什么、热度如何,以及来源是否可靠。
- 目录范围
- 已验证
- Skills
- 5,771
- 仓库
- 824
- 最近同步
- 2026年9月8日
yaklangreverse-shell-techniques
- Reverse shell techniques playbook. Use when establishing remote shells including language one-liners, encrypted shells (OpenSSL/socat/ncat), web shells, PTY upgrades, file transfer methods, PowerShell shells, and Windows payload generation.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangrsa-attack-techniques
- RSA attack playbook for CTF and real-world cryptanalysis. Use when given RSA parameters (n, e, c) and need to recover plaintext by exploiting weak keys, small exponents, shared factors, or padding oracles.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangsaml-sso-assertion-attacks
- SAML SSO assertion attack playbook. Use when testing signature validation, assertion wrapping, audience restrictions, ACS handling, XML trust boundaries, and enterprise SSO flaws.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangsandbox-escape-techniques
- Sandbox escape playbook. Use when breaking out of Python sandbox, Lua sandbox, seccomp filter, chroot jail, container/Docker, browser sandbox, or namespace isolation to achieve unrestricted code execution or file access.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangsmart-contract-vulnerabilities
- Smart contract vulnerability playbook. Use when auditing Solidity/EVM contracts for reentrancy, integer overflow, access control, delegatecall, flash loan, signature replay, and MEV-related attack patterns.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangsqli-sql-injection
- SQL injection playbook. Use when input reaches SQL queries, authentication logic, sorting, filtering, reporting, or DB-specific blind and out-of-band execution paths.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangssrf-server-side-request-forgery
- SSRF playbook. Use when the server fetches URLs, resolves hostnames, imports remote content, or can be driven toward internal networks, cloud metadata, or secondary protocols.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangssti-server-side-template-injection
- SSTI playbook. Use when template expressions, server-side rendering, preview features, or templating engines may evaluate attacker-controlled content.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangstack-overflow-and-rop
- Stack overflow and ROP playbook. Use when exploiting buffer overflows to hijack control flow via return address overwrite, ROP chains, ret2libc, ret2csu, ret2dlresolve, or SROP on Linux userland binaries.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangsteganography-techniques
- Steganography detection and extraction playbook. Use when analyzing images (LSB, PNG chunks, JPEG DCT, EXIF), audio (spectrogram, DTMF), files (polyglots, appended data, ADS), and text (whitespace, zero-width, homoglyphs) for hidden data.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangsubdomain-takeover
- Subdomain takeover detection and exploitation playbook. Use when targets have dangling CNAME/NS/MX records pointing to deprovisioned cloud resources, expired third-party services, or unclaimed SaaS tenants that an attacker can register to serve content under the victim's domain.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangsymmetric-cipher-attacks
- Symmetric cipher attack playbook. Use when exploiting block cipher mode weaknesses (CBC padding oracle, ECB cut-and-paste, bit flipping), stream cipher key reuse, or meet-in-the-middle attacks.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangtraffic-analysis-pcap
- Traffic analysis and PCAP forensics playbook. Use when analyzing network captures including Wireshark filters, protocol analysis (HTTP/DNS/FTP/SMTP/USB/WiFi), data extraction, covert channel detection, PCAP repair, TLS decryption, and tshark command-line analysis.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangtunneling-and-pivoting
- Tunneling and pivoting playbook. Use when establishing network tunnels through compromised hosts including SSH tunneling, Chisel, Ligolo-ng, socat, DNS/ICMP/HTTP tunneling, ProxyChains, and multi-layer pivoting strategies.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangtype-juggling
- PHP type juggling and weak comparison (==) bypass. Use when authentication, HMAC/signature checks, or token validation uses loose equality, numeric coercion, or hash comparisons without strict types — common in legacy PHP and CTF-style code paths.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangunauthorized-access-common-services
- Unauthorized access playbook for common exposed services. Use when Redis, Rsync, PHP-FPM, AJP/Ghostcat, Hadoop YARN, H2 Console, or similar management interfaces are exposed without authentication.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangupload-insecure-files
- Insecure file upload playbook. Use when testing upload validation, storage paths, processing pipelines, preview behavior, overwrite risks, and upload-to-RCE chains.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangvm-and-bytecode-reverse
- Custom VM and bytecode reverse engineering playbook. Use when CTF challenges or protected software implement custom virtual machines with proprietary bytecode, dispatcher loops, or maze-style challenges.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangwaf-bypass-techniques
- WAF bypass methodology and generic evasion techniques. Use when a web application firewall blocks injection payloads (SQLi, XSS, RCE) and you need to craft bypasses using encoding, protocol-level tricks, or WAF-specific weaknesses.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangweb-cache-deception
- Web cache deception and poisoning playbook. Use when CDN, reverse proxy, or application caching may serve sensitive authenticated content to other users due to path confusion or cache key manipulation.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangwebsocket-security
- WebSocket handshake, CSWSH, tooling (wsrepl, ws-harness, Burp), and common flaws. Use when apps use real-time channels, chat, notifications, or WS-backed APIs.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangwindows-lateral-movement
- Windows lateral movement playbook. Use when pivoting between Windows hosts via PsExec, WMI, WinRM, DCOM, RDP, pass-the-hash, overpass-the-hash, or pass-the-ticket techniques.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangwindows-privilege-escalation
- Windows local privilege escalation playbook. Use when you have low-privilege shell access on Windows and need to escalate via token abuse, Potato exploits, service misconfigurations, DLL hijacking, UAC bypass, or registry autoruns.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日
yaklangxslt-injection
- XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. Use when user-controlled XSLT/stylesheet input or transform endpoints are in scope.
- 安装量
- 2
- GitHub Stars
- 2006
- 最近更新
- 6月16日