面向 Claude Code 的专业渗透测试技能模块。严格遵循 PTES 标准,覆盖信息收集、漏洞利用、后渗透与免杀规避全阶段。不定期更新skill,以达到优化skill。
☆198Jun 5, 2026Updated last month
Alternatives and similar repositories for SecSkills
Users that are interested in SecSkills are comparing it to the libraries listed below. We may earn a commission when you buy through links labeled 'Ad' on this page.
Sorting:
- 收集整理渗透测试、漏洞扫描、代码审计、CTF、逆向、安全研究 等网络安全相关的 Skills和MCP☆790Jul 6, 2026Updated 3 weeks ago
- 实战 SRC / 众测 / Bug bounty 漏洞挖掘 Claude Code skill — 19 个攻击类 playbook、305 个结构化 payload、263 个 WAF/EDR 绕过、2887 份 HackerOne 真实案例、88,636 WooYun …☆594May 24, 2026Updated 2 months ago
- 💬 🚀 告别繁琐命令行,用自然语言驱动专业级渗透测试。 ⚡ 让安全测试从未如此简单、高效。Forget complex command lines. 🛡️ Professional penetration testing, powered by natural lan…☆264Jun 4, 2026Updated 2 months ago
- 网站渗透测试 Skill — 目标识别、CDN/WAF检测、指纹架构、API发现、端口扫描、未授权与漏洞验证☆28Jun 8, 2026Updated last month
- 🛡️ 自动化渗透测试调度平台 — Claude Code 生态. AI 驱动 / 多目标并发 / 动态 skill 加载 / 实时观测☆21Jul 8, 2026Updated 3 weeks ago
- Proton VPN Special Offer - Get 70% off • AdSpecial partner offer. Trusted by over 100 million users worldwide. Tested, Approved and Recommended by Experts.
- SecKnowledge - Web与AI安全测试知识技能☆350Jun 17, 2026Updated last month
- 一个针对业务系统功能的全自动化平台☆60Jun 10, 2026Updated last month
- OneScan扩展,原项目已停更,此项目为二开项目,插件ID精简为OST☆50Updated this week
- Professional file upload vulnerability testing tool with 263+ bypass techniques, proxy capture, dynamic scanning(专业的文件上传漏洞检测工具,支持263+绕过技术…☆215Apr 11, 2026Updated 3 months ago
- 自用yakit规则分享☆49Apr 18, 2025Updated last year
- 综合漏洞后渗透利用工具☆1,777Dec 11, 2025Updated 7 months ago
- 基于已收集指纹库进行识别网站指纹的浏览器插件☆121Jul 30, 2025Updated last year
- 🛡️ 网络安全/AI Agent Skills 集合 | Cybersecurity Security Skills Collection☆263Jun 25, 2026Updated last month
- 基于 Burp Montoya API 开发的全能插件,集成自动化HTTP加解密、高危漏洞扫描(Fastjson/Log4j/Shiro/Spring未授权)与安全工具联动(sqlmap/xray),支持 Burp Collaborator 与 CEYE DNSLog,专为…☆43Jun 11, 2026Updated last month
- Deploy to Railway using AI coding agents - Free Credits Offer • AdUse Claude Code, Codex, OpenCode, and more. Autonomous software development now has the infrastructure to match with Railway.
- Zack-AI-Scanner 是一款基于大语言模型的自动化 Web 漏洞扫描工具,作为 Burp Suite 扩展运行。通过 AI 深度学习技术自动分析 HTTP 请求特征,智能识别潜在安全漏洞,动态生成针对性测试Payload,并智能验证漏洞真实性。☆89Apr 13, 2026Updated 3 months ago
- 红队浏览器插件-检测VUE站点未授权漏洞☆906May 7, 2026Updated 2 months ago
- Hengge team develops JavaScript specifically for loading Webpack for batch reading☆318Jun 11, 2026Updated last month
- GYscan是一款基于Go语言开发的现代化综合渗透测试工具,专为安全研究人员、渗透测试工程师和红队成员设计。项目采用模块化架构,包含C2服务器端和客户端组件,支持Windows和Linux平台,提供系统安全分析和漏洞扫描功能。☆85Jul 6, 2026Updated 3 weeks ago
- 一个新的安全服务工具集☆41Updated this week
- AutoFuzz是一款安全测试的辅助型BurpSuite插件,主要用于自动识别请求中的参数,根据预设的payload逐个发包测试,从而提高测试效率。☆115Jun 2, 2025Updated last year
- 一款轻量级 Burp Suite 被动扫描探测SQLi XSS SSTI漏洞插件☆87Mar 18, 2026Updated 4 months ago
- Vibe Pentest(AI 渗透测试)是一款基于 AI Agent 架构的自动化渗透测试工具,采用多 Agent 并行执行架构,能够对 Web 应用、API、管理后台等进行全面的黑盒渗透测试(包括业务逻辑漏洞评估),输出稳定可靠的安全报告,并提供可落地的整改建议。☆237Jul 16, 2026Updated 2 weeks ago
- JDumpSpiderGUI 是一个用于 Java 堆转储 文件分析的工具,支持命令行和 JavaFX 图形界面两种模式。该工具主要是在原工具上添加了图形化的界面☆175May 5, 2025Updated last year
- Serverless GPU API endpoints on Runpod - Get Bonus Credits • AdSkip the infrastructure headaches. Auto-scaling, pay-as-you-go, no-ops approach lets you focus on innovating your application.
- Luvv-MCP 是一个 AI 原生的前端安全分析引擎,接入 Claude Code 后,你说一句"帮我审计这个网站",AI 就能自动完成技术栈识别(1.8 万条规则覆盖 CMS/框架/CDN/中间件)、泄露扫描(阿里云 AK、GitHub Token、Webhoo…☆28Jun 12, 2026Updated last month
- 掘地三尺(DigDeep):覆盖云安全 、小程序、APP、web等常见敏感信息泄露类型,一键挖掘源码中的密码/密钥/手机号/身份证/云服务AK、SK等近百类敏感数据。☆77Apr 12, 2026Updated 3 months ago
- PHP-Code-Audit-Skill是一个专注于PHP代码审计的Skill☆380Mar 25, 2026Updated 4 months ago
- Nuclei POC 管理与漏洞验证工具-Nuclei GUI☆552Apr 24, 2026Updated 3 months ago
- 开源项目,所有项目仅供参考学习,禁止用于任何违法行为,任何违法行为需使用者本人自己承担相应法律责任。☆86Jan 17, 2026Updated 6 months ago
- Chrome 浏览器插件-企业弱口令字典生成工具☆47May 21, 2026Updated 2 months ago
- YongYou U8C deserialization file upload exploit tool targeting IPFxxFileService and IFileTrans services☆28Sep 28, 2025Updated 10 months ago
- 微信小程序全自动安全审计 Skill,基于 Claude Code Agent Teams。7 Agent 协作,覆盖敏感信息、API接口、加密分析、漏洞分析四大维度。采用脚本+LLM双层架构,脚本保证覆盖率,LLM保证准确率。☆370Apr 3, 2026Updated 4 months ago
- Finger 是一款专为 Burp Suite 打造的模块化指纹识别插件,旨在通过被动流量监控与智能主动探测,快速识别目标站点的技术栈(CMS、框架、中间件、API 接口及敏感路径泄露)☆30Apr 13, 2026Updated 3 months ago
- 1-Click AI Models by DigitalOcean Gradient • AdDeploy popular AI models on DigitalOcean Gradient GPU virtual machines with just a single click. Zero configuration with optimized deployments.
- JeecgBoot Go版本综合漏洞检测工具☆103Feb 24, 2026Updated 5 months ago
- 致命精准的红队作战兵器。模块化集成资产发现、漏扫与利用,重新定义渗透测试工作流 (Workflow) 的新一代安全平台。☆392Jun 29, 2026Updated last month
- TsoJanScan Burp Plugins Secondary Development☆103Jan 15, 2026Updated 6 months ago
- 适用于红队攻防演练获得目标账户批量登录,报告编写☆103Nov 18, 2025Updated 8 months ago
- Burpsuite存储桶配置不当漏洞检测插件☆199Jul 16, 2025Updated last year
- Burp suite 短信轰炸辅助绕过插件☆421Jun 25, 2026Updated last month
- 一款综合性网络安全检测和运维工具,旨在快速资产发现、识别、检测,构建基础资产信息库,协助甲方安全团队或者安全运维人员有效侦察和检索资产,发现存在的薄弱点和攻击面。☆4,105Jul 26, 2026Updated last week