Search
Security · PHP
Skills
Sort:BestMost starsTrending todayTrending this weekTrending this monthNewestRecently updatedName
| # | Skill | Repository | Stars | Used in | Tokens | Auto-check | Licence | Updated |
|---|---|---|---|---|---|---|---|---|
| 49 | XSLT injection testing: processor fingerprinting, XXE and document() SSRF, EXSLT write primitives, PHP/Java/.NET extension RCE surfaces. | langbyyi/ | 129 | 1 repo | ~3k | Automated safety check: Pass | Apache-2.0 | 4 days ago |
| 50 | Detect and exploit local and remote file inclusion vulnerabilities for sensitive data access and code execution | NeoTheCapt/ | 143 | — | ~988 | Automated safety check: Warn | No licence | 2 mo ago |
| 51 | 51.Sast Rce Detect Remote Code Execution (RCE) vulnerabilities in a codebase using a three-phase approach: recon (find dangerous execution sinks), batched verify (trace user input to sinks in parallel… | utkusen/ | 1.3k | — | ~8.3k | Automated safety check: Pass | MIT | 6 mo ago |
| 52 | Mass scan for exposed env files, backups, and git configs. An agent skill from uphiago/recon-skills. | uphiago/ | 1.3k | — | ~2.2k | Automated safety check: Notes | MIT | 1 mo ago |
| 53 | WordPress plugin development with hooks, security, REST API, custom post types. | secondsky/ | 227 | — | ~4.6k | Automated safety check: Pass | MIT | 13 days ago |
| 54 | Hunt Insecure Deserialization | sickn33/ | 47k | 1 repo | ~2.1k | Automated safety check: Notes | MIT | 2 days ago |
| 55 | Hunt file upload bugs | sickn33/ | 47k | 1 repo | ~2.4k | Automated safety check: Pass | MIT | 2 days ago |
| 56 | Insecure deserialization hunting across Java / .NET / PHP / Python / Ruby / Node. | Encod3d-Sec/ | 329 | — | ~1.7k | Automated safety check: Pass | MIT | 1 mo ago |
| 57 | WordPress security code review and vulnerability detection. An agent skill from jorgerosal/wordpress-skills. | jorgerosal/ | 103 | — | ~6.4k | Automated safety check: Pass | MIT | 4 mo ago |
| 58 | Audit PHP web application source for critical vulnerabilities using PHP's specific sink and footgun catalog — object injection via unserialize and phar:// POP chains, type-juggling and magic-hash… | trilwu/ | 157 | — | ~2.8k | Automated safety check: Pass | MIT | 1 mo ago |
| 59 | CTF 挑战中的源码审计方法。当发现 .git 目录、.bak/.zip 备份、/proc/self/environ 泄露源码时使用。与真实代码审计不同——CTF 源码中的漏洞是故意设置的,通常只有 1-2 个关键点。先找危险函数(sink),再追溯输入(source)到该函数的路径。覆盖 PHP/Python/Node.js/Java 四种语言的危险函数和漏洞模式 | wgpsec/ | 1.8k | — | ~1.4k | Automated safety check: Notes | No licence | yesterday |
| 60 | 60.Php Security PHP-only security standards for database access, password handling, and input validation. | HoangNguyen0403/ | 572 | — | ~604 | Automated safety check: Pass | MIT | yesterday |
| 61 | Security pattern matching for code audit and content inspection: grep strings for source auditing, malicious-string signatures, PHP magic hashes, error-message patterns. | Ch1nfo/ | 114 | — | ~425 | Automated safety check: Pass | MIT | 19 days ago |
| 62 | Webshell samples for detection and analysis webshell 样本: PHP, ASP, ASPX, JSP, Python, Perl shells. | Ch1nfo/ | 114 | — | ~306 | Automated safety check: Pass | MIT | 19 days ago |
| 63 | Static ReDoS (Regular Expression Denial of Service) vulnerability scanner and regex quality auditor for codebases. | LeoYeAI/ | 2.2k | — | ~5.1k | Automated safety check: Pass | Apache-2.0 | 2 mo ago |
| 64 | CTF/靶场 Flag 强制验证流程。当通过任何方式发现疑似 flag 字符串(含 flag{、FLAG{、ctf{ 等格式)时必须立即使用此 skill 验证,不要直接提交。防止因字符截断、编码错误、HTML 实体、base64 不完整解码、hex 截断等原因导致提交错误 flag。即使 flag 看起来完整,也可能存在隐藏字符或编码问题。覆盖 SQL… | wgpsec/ | 1.8k | — | ~644 | Automated safety check: Pass | No licence | yesterday |
| 65 | CTF Web 挑战专用侦察方法。当面对 CTF 靶场目标需要快速发现攻击入口时使用。与真实渗透的 recon 不同——CTF 是单个应用、有意留线索、侦察应在 2-3 轮内完成。覆盖源码泄露、备份文件、隐藏路径、页面线索提取 | wgpsec/ | 1.8k | — | ~624 | Automated safety check: Notes | No licence | yesterday |
| 66 | 使用 dirsearch 进行 Web 目录和文件暴力枚举。当需要发现隐藏的目录、文件、后台路径、备份文件时使用。dirsearch 内置高质量字典,支持多扩展名、递归扫描、状态码过滤。任何涉及目录枚举、路径发现、后台查找、敏感文件发现的场景都应使用此技能 | wgpsec/ | 1.8k | — | ~520 | Automated safety check: Pass | No licence | yesterday |
| 67 | 当拿到源码、代码片段、反编译产物,或用户要求代码审计时调用。负责输入点→传播链→危险函数Sink的静态审计,跨语言(PHP/Java/Python/Node/Go)危险函数速查,输出可疑调用链与缺陷触发条件。 | zhaji2333/ | 115 | — | ~409 | Automated safety check: Pass | MIT | 26 days ago |
| 68 | 68.Php Tooling Configure PHP ecosystem tooling, dependency management, and static analysis. | HoangNguyen0403/ | 572 | — | ~615 | Automated safety check: Pass | MIT | yesterday |
| 69 | PHP 源码认证、配置与逻辑类漏洞审计。当在 PHP 白盒审计中需要检测认证绕过、 权限控制、安全配置、密码学误用或业务逻辑漏洞时触发。 | wgpsec/ | 1.8k | — | ~704 | Automated safety check: Pass | No licence | yesterday |
| 70 | PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。 | wgpsec/ | 1.8k | — | ~767 | Automated safety check: Notes | No licence | yesterday |
| 71 | PHP 源码前端交互类漏洞审计。当在 PHP 白盒审计中需要检测前端安全相关漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~777 | Automated safety check: Pass | No licence | yesterday |
| 72 | PHP 源码序列化与模板类漏洞审计。当在 PHP 白盒审计中需要检测反序列化、XML 解析或模板注入漏洞时触发. An agent skill from wgpsec/AboutSecurity. | wgpsec/ | 1.8k | — | ~689 | Automated safety check: Pass | No licence | yesterday |
| 73 | Information disclosure detection — error messages, files, headers, debug endpoints | NeoTheCapt/ | 143 | — | ~1.1k | Automated safety check: Notes | No licence | 2 mo ago |
| 74 | 74.Ssti Testing Server-side template injection detection, engine identification, and RCE | NeoTheCapt/ | 143 | — | ~748 | Automated safety check: Pass | No licence | 2 mo ago |