Secknowledge Skill
Pa55w0rd/secknowledge-skill
Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。
Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-kernel --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-kernel .claude/skills/alibabacloud-ecs-sec-kernel && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "alibabacloud-ecs-sec-kernel" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-kernel into .claude/skills/alibabacloud-ecs-sec-kernel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-kernel", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-kernelType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-kernel --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-kernel .agents/skills/alibabacloud-ecs-sec-kernel && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "alibabacloud-ecs-sec-kernel" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-kernel into .agents/skills/alibabacloud-ecs-sec-kernel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-kernel", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-kernel --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-kernel .cursor/skills/alibabacloud-ecs-sec-kernel && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "alibabacloud-ecs-sec-kernel" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-kernel into .cursor/skills/alibabacloud-ecs-sec-kernel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-kernel", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git --path skills/alibabacloud-ecs-sec-kernel--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-kernel --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-kernel .gemini/skills/alibabacloud-ecs-sec-kernel && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "alibabacloud-ecs-sec-kernel" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-kernel into .gemini/skills/alibabacloud-ecs-sec-kernel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-kernel", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-kernelInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-kernel .github/skills/alibabacloud-ecs-sec-kernel && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "alibabacloud-ecs-sec-kernel" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-kernel into .github/skills/alibabacloud-ecs-sec-kernel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-kernel", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aliyun/alibabacloud-ecs-troubleshoot-skills alibabacloud-ecs-sec-kernel --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/alibabacloud-ecs-sec-kernel .opencode/skills/alibabacloud-ecs-sec-kernel && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "alibabacloud-ecs-sec-kernel" agent skill from https://github.com/aliyun/alibabacloud-ecs-troubleshoot-skills/tree/main/skills/alibabacloud-ecs-sec-kernel into .opencode/skills/alibabacloud-ecs-sec-kernel/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "alibabacloud-ecs-sec-kernel", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
alibabacloud-ecs-sec-kernelLinux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.
Alibabacloud Ecs Sec Kernel is an agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills. Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计。 88 个内核 CVE 检测器(2003-2026),覆盖 Netfilter/eBPF/TLS/iouring/xfrm 等子系统的本地提权(LPE)漏洞。 采用 CTF 挑战模式客观验证漏洞可利用性:nobody 用户通过内核漏洞写入/读取 root 文件即为提权成功。 PoC 二进制从源码动态编译(--compile-poc),无需预置二进制文件。需要 root 权限(sudo)运行。 与 sec-userspace(用户态入侵检测)互补,共同构成完整的 ECS 安全评估方案。 务必在检测内核漏洞时使用此技能。每当需要验证 CVE 或执行 PoC 验证时,优先调用此技能。 当用户提到内核安全、CVE 检测、漏洞利用验证、提权漏洞时,主动触发。
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 826 other files, including scripts, reference files and assets (for example `CHANGELOG.md`, `CONTRIBUTOR.md` and `__init__.py`).
It sits in Security, covering Vulnerability scanning and Capture the flag. It works with Alibaba Cloud and Linux. The repository describes itself as: Troubleshooting skills for Alibaba Cloud ECS. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 809887f. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
terminal (sudo required)file-readfile-writeFrom allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell and Python, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
python3From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Alibabacloud Ecs Sec Kernel loads about 2.4k tokens when it runs, and up to ~7.7k if it reads all its reference files. Until then it costs about 100 tokens; SKILL.md has 414 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
- terminal (sudo required)sudo python3 -m scripts --compile-poc --verbosesudo python3 -m scripts --verbosesudo python3 -m scripts --cve-id CVE-2026-31431 -vsudo python3 -m scripts --format json -vAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from aliyun/alibabacloud-ecs-troubleshoot-skills at commit 809887f, republished under its Apache-2.0 licence (© aliyun). 414 words, ~2,371 tokens.
.claude/skills/alibabacloud-ecs-sec-kernel/SKILL.md (or your agent's skills folder). This skill also uses 822 other files; get the full folder from GitHub.Linux 内核 CVE 漏洞检测与 PoC 验证工具。88 个内核漏洞检测器,CTF 挑战模式验证。
Version: 1.4.1 (JSON-driven architecture)
当以下场景出现时,务必主动调用此技能:
PoC 验证可能导致 kernel crash (panic/hang/deadlock),建议在隔离的虚拟机/可快照环境中运行。 PoC 不会永久改写系统文件,不会进行持久化提权。所有临时修改均在 Post 阶段完整恢复。 使用本工具即表示您同意遵守 完整安全声明 中的所有条款。 违规使用需承担全部法律责任。
# 从 skill 根目录执行:
# 需要 root 权限(sudo)
# 首次运行:编译 PoC 二进制 + 全量检测(推荐)
sudo python3 -m scripts --compile-poc --verbose
# 全量检测与 PoC 验证(poc-bin 已编译后)
sudo python3 -m scripts --verbose
# 单 CVE 验证
sudo python3 -m scripts --cve-id CVE-2026-31431 -v
# 列出所有检测器(无需 root)
python3 -m scripts --list-detectors
# 输出 JSON 格式报告
sudo python3 -m scripts --format json -v| 参数 | 类型 | 默认值 | 说明 |
|---|---|---|---|
--mode | choice | host | 运行模式(仅 host,Linux 服务器环境) |
--poc-output | path | ./workspace | PoC 证据输出目录 |
--poc-timeout | int | 30 | PoC 执行超时时间(秒) |
--no-prepare | flag | off | 跳过 Prepare 阶段 |
--no-post | flag | off | 跳过 Post 阶段 |
--poc-user | string | nobody | Run 阶段执行用户(降权执行) |
--no-force-demote | flag | off | 不强制降权到非特权用户 |
--compile-poc | flag | off | 自动编译缺失的 PoC 二进制文件(plain 模式) |
--output-dir | path | ./workspace | 报告输出目录 |
--format | choice | markdown | 报告格式(markdown / json) |
--cve-id | string | - | 仅检测指定 CVE |
--config | path | - | 配置文件路径 |
--verbose / -v | flag | off | 详细输出 |
--list-detectors | flag | off | 列出所有检测器(无需 root) |
默认行为: 所有在 kernel_cves.yaml 中 enabled: true 的 CVE 都会自动执行 PoC 验证,无需额外参数。唯一跳过 PoC 的条件是将 CVE 设置为 enabled: false。
--compile-poc: 当 poc-bin/ 目录下缺少对应 ELF binary 时,自动调用 poc-src/build.sh 编译。首次运行时必须使用此参数(poc-bin/ 不再随仓库分发,需从源码动态编译)。
Why: PoC 二进制从源码动态编译,避免在 git 中存储大量 ELF 文件。编译采用静态链接 + strip,确保跨发行版兼容。
--no-prepare / --no-post: 跳过三阶段验证中的 Prepare 或 Post 阶段。用于调试目的,生产环境建议保留完整三阶段。
--poc-user: Run 阶段以指定用户身份执行 PoC binary,默认 nobody(uid=65534)。用于验证 LPE(本地提权)路径。
--no-force-demote: 默认情况下 PoC 执行会强制降权到 --poc-user 指定的非特权用户。此参数禁用强制降权。
PoC 三阶段验证需要 root 权限的原因:
modprobe algif_aead、modprobe esp4 等)、创建 root 拥有的目标文件、配置 xfrm SA/SP 等安全策略CTF 挑战模式的设计理由:
setuid(0),只是通过文件操作证明漏洞可被利用| 指标 | 数量 |
|---|---|
| 总检测器数 | 88 |
| write_root_file 模式 | 84 |
| read_root_file 模式 | 24 |
| uaf 模式 | 5 |
每次执行完成后自动输出详细统计报表,包含:
| 模式 | 目标文件权限 | 验证方式 | 数量 |
|---|---|---|---|
write_root_file | root:root 0644 | nobody 通过内核漏洞写入 root 文件 | 86 |
read_root_file | root:root 0400 | nobody 通过内核漏洞读取 root 文件 | 24 |
uaf | N/A | Use-After-Free 利用验证 | 5 |
[PoC-IMPL] 标签区分环境问题和代码问题)==============================================================
sec-kernel v1.4.1 - Linux Kernel CVE Detection
==============================================================
Kernel: 5.15.0-91-generic (x86_64)
Mode: host (Linux Server)
==============================================================
==============================================================
Detection Summary
==============================================================
Total CVEs checked: 88
Vulnerable: 3
Not Vulnerable: 80
Uncertain: 2
PoC Exploitable: 2
Execution time: 45.32s
==============================================================================================================================
sec-kernel PoC Execution Statistics
================================================================
Total Detectors: 88 (with PoC capability)
PoC Executed: 83
------------------------------------------------------------
SUCCESS (ran correctly): 78
+- EXPLOITABLE: 2 (vulnerability confirmed)
+- NOT_EXPLOITABLE: 76 (kernel patched/mitigated)
------------------------------------------------------------
FAILED (execution error): 5
+- TIMEOUT: 2
+- CRASH: 1
+- MISSING_BIN: 0
+- PARSE_ERROR: 2
+- PERMISSION: 0
------------------------------------------------------------
SKIPPED: 2
+- NO_MODULE: 2
------------------------------------------------------------
Execution Time: 45.32s
================================================================⚠️ SECURITY DISCLAIMER / 安全声明
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
本工具仅限在已授权的隔离测试环境中使用。
严禁用于生产环境或未授权系统。违规使用需承担全部法律责任。
━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━
[Phase 1: Prepare] (root)
✓ Loaded kernel module: algif_aead
✓ Created target file: /tmp/sec-kernel-poc-XXXX/poc_target (root:root 0644)
✓ Initial content: writeme_a3f8b2c1
[Phase 2: Run] (nobody, uid=65534)
CTF_READ_BEFORE:writeme_a3f8b2c1
CTF_WRITE:ctf{164d74cd804f9361} (attempting...)
CTF_READ_AFTER:ctf{164d74cd804f9361}
CTF_FLAG:ctf{164d74cd804f9361}
POC_RESULT:EXPLOITABLE
[Phase 3: Post] (root)
✓ File content verified: ctf{164d74cd804f9361} ✓ MATCH
✓ Cleanup completed
✓ System state restored
[RESULT] CVE-2026-31431: EXPLOITABLE (confidence=0.95)| 字段 | 含义 |
|---|---|
CTF_READ_BEFORE: | PoC 执行前读取的原始文件内容 |
CTF_WRITE: | PoC 尝试写入的 CTF 值 |
CTF_READ_AFTER: | PoC 执行后读取的文件内容 |
CTF_FLAG:ctf{xxx} | 漏洞利用成功的标志值 |
POC_RESULT:EXPLOITABLE | 漏洞可利用 |
POC_RESULT:NOT_EXPLOITABLE | 漏洞不可利用(内核已修复) |
| 结果 | 含义 | 建议操作 |
|---|---|---|
| EXPLOITABLE | 当前内核存在可利用漏洞 | 立即升级内核 |
| NOT_EXPLOITABLE | 漏洞条件不满足或已修复 | 无需操作 |
| DETECTION_ONLY | 版本匹配但未执行 PoC | 建议进一步验证 |
以下 CVE 已在真实内核环境中通过 CTF 挑战模式验证提权成功(EXPLOITABLE),CTF flag 每次随机生成。
[Phase 1: Prepare] (root)
Created CTF target: /tmp/sec-kernel-poc-XXXX/poc_target_canary
mode=write_root_file, uid=0, perm=644
Initial content: writeme_f9de12afe0d6da5a
[Phase 2: Run] (nobody, uid=65534)
CTF_WRITE:ctf{dddb28301f24e3db} (attempting...)
CTF_FLAG:ctf{dddb28301f24e3db}
POC_RESULT:EXPLOITABLE
[Phase 3: Post] (root)
CTF write_root_file PASSED: inner value matches (dddb28301f24e3db)
Rollback executed: target file removed
System state restored
[RESULT] CVE-2026-31431: EXPLOITABLE (confidence=0.95)
Kernel: 6.6.87.2-microsoft-standard-WSL2
Exploit path: AF_ALG AEAD authencesn + splice() -> page cache corruption[Phase 1: Prepare] (root)
Created CTF target: /tmp/sec-kernel-poc-XXXX/poc_target_dirtyfrag
mode=write_root_file, uid=0, perm=644, size=4096
Module state snapshot: esp4=loaded
[Phase 2: Run] (nobody, uid=65534)
CTF_WRITE:ctf{ab2084cd52cdad11} (attempting via rxrpc/rxkad...)
RxRPC variant failed (EAFNOSUPPORT), trying ESP/xfrm fallback...
CTF_WRITE:ctf{ab2084cd52cdad11} (attempting via esp/xfrm fallback...)
CTF_FLAG:ctf{ab2084cd52cdad11}
POC_RESULT:EXPLOITABLE
[Phase 3: Post] (root)
CTF write_root_file PASSED: inner value matches (ab2084cd52cdad11)
Rollback executed: target file removed
System state restored
[RESULT] CVE-2026-PENDING-DIRTYFRAG: EXPLOITABLE (confidence=0.95)
Kernel: 6.6.87.2-microsoft-standard-WSL2
Exploit path: ESP/xfrm variant (RxRPC fallback) -> splice() page cache write
Dual-variant: RxRPC (Ubuntu 24.04) / ESP (WSL2) automatic fallbackPhase 1 (root): 准备环境 — 加载模块、创建目标文件、记录初始状态
Phase 2 (nobody): 执行 PoC — 读原值 → 漏洞利用写入 → 读回验证
Phase 3 (root): 验证清理 — 独立确认写入结果、恢复系统状态完整 CVE 检测列表见 references/cve-list.md(88 个内核漏洞检测器,全部启用 CTF 挑战模式验证)。
覆盖子系统:Netfilter/nf_tables (18) | eBPF/BPF (8) | Network/Socket (12) | TLS (7) | io_uring (3) | Memory/Page Cache (5) | Filesystem (3) | IPsec/xfrm (3) | ptrace/cred (3) | Others (23)
PoC 执行日志:workspace/poc-{CVE-ID}.log
回退路径:/tmp/poc-{CVE-ID}.log(workspace 不可写时)
© aliyun, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 822 other files (scripts, references, assets) in skills/alibabacloud-ecs-sec-kernel of aliyun/alibabacloud-ecs-troubleshoot-skills.
Open the folder on GitHubat commit 809887f
Alibabacloud Ecs Sec Kernel next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Alibabacloud Ecs Sec Kernel this skillaliyun/alibabacloud-ecs-troubleshoot-skills | 148 | — | ~2.4k | Automated safety check: Notes | Apache-2.0 | |
| Secknowledge SkillPa55w0rd/secknowledge-skill | 425 | — | ~2.7k | Automated safety check: Pass | None | |
| Ctf Cryptoljagiello/ctf-skills | 3.4k | — | ~11k | Automated safety check: Notes | MIT | |
| Remediate Image Cveskubernetes-sigs/cloud-provider-azure | 294 | — | ~3.9k | Automated safety check: Pass | Apache-2.0 | |
| Network Scannerptn1411/skill | 219 | — | ~1.4k | Automated safety check: Notes | None | |
| Ctf Forensicswgpsec/AboutSecurity | 1.8k | — | ~878 | Automated safety check: Notes | None |
Pa55w0rd/secknowledge-skill
Web+AI 安全测试知识库。融合 WooYun 88,636 案例 + 先知 L1-L4 方法论 + GAARM 173 风险 + OWASP Top 10 (LLM/ASI/WSTG)。
ljagiello/ctf-skills
Provides cryptography attack techniques for CTF challenges. An agent skill from ljagiello/ctf-skills.
kubernetes-sigs/cloud-provider-azure
Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification…
ptn1411/skill
Run authorized network reconnaissance with Nmap on Windows (or Linux).
wgpsec/AboutSecurity
CTF 数字取证与信号分析技术。当挑战提供磁盘镜像(.dd/.E01)、内存 dump(.raw/.vmem)、网络抓包(.pcap/.pcapng)、隐写图片/音频、Windows 事件日志(.evtx)时使用。覆盖 Volatility 内存分析、Wireshark 流量还原、binwalk 隐写提取、文件系统恢复等取证全链路
vinayaklatthe/microsoft-security-skills
Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation…
aliyun/alibabacloud-ecs-troubleshoot-skills
Linux 用户态安全入侵检测与取证工具,专为 AI Agent 设计。自动判断服务器是否被入侵, 提供完整证据链和可执行修复建议。51 个安全分析器覆盖进程/网络/认证/持久化/Rootkit/ 恶意软件/内存取证/容器逃逸等 12 类检测维度,10 个数据采集器全面采集系统状态, 映射 103+ MITRE ATT&CK 技术,支持 standalone/docker/k8s 三种部署模式。
aliyun/alibabacloud-ecs-troubleshoot-skills
Troubleshoot an Alibaba Cloud ECS Linux OS. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.
aliyun/alibabacloud-ecs-troubleshoot-skills
Troubleshoot and repair Alibaba Cloud ECS Windows instances from inside the GuestOS or remotely via Cloud Assistant.
Works with
Categories
Linux 内核态 CVE 漏洞检测与 PoC 验证工具,专为 AI Agent 设计. An agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills. Alibabacloud Ecs Sec Kernel is an agent skill from aliyun/alibabacloud-ecs-troubleshoot-skills.
Alibabacloud Ecs Sec Kernel fits situations like: tasks that involve Vulnerability scanning; tasks that involve Capture the flag.
Run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a claude-code`. Or copy the skill folder (skills/alibabacloud-ecs-sec-kernel in aliyun/alibabacloud-ecs-troubleshoot-skills) into .claude/skills/alibabacloud-ecs-sec-kernel in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a codex`. Or copy the skill folder (skills/alibabacloud-ecs-sec-kernel in aliyun/alibabacloud-ecs-troubleshoot-skills) into .agents/skills/alibabacloud-ecs-sec-kernel in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aliyun/alibabacloud-ecs-troubleshoot-skills --skill alibabacloud-ecs-sec-kernel -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/alibabacloud-ecs-sec-kernel, .gemini/skills/alibabacloud-ecs-sec-kernel, .github/skills/alibabacloud-ecs-sec-kernel and .opencode/skills/alibabacloud-ecs-sec-kernel in your project.
Going by SKILL.md and its folder, Alibabacloud Ecs Sec Kernel needs a shell and Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3; A Bash shell. Its frontmatter pre-approves these tools: terminal (sudo required), file-read, file-write.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Alibabacloud Ecs Sec Kernel is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Alibabacloud Ecs Sec Kernel: Secknowledge Skill (Pa55w0rd/secknowledge-skill, 425 stars), Ctf Crypto (ljagiello/ctf-skills, 3.4k stars), Remediate Image Cves (kubernetes-sigs/cloud-provider-azure, 294 stars) and Network Scanner (ptn1411/skill, 219 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aliyun (a GitHub organization) maintains it in aliyun/alibabacloud-ecs-troubleshoot-skills, which has 148 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on August 20, 2026.
Source: aliyun/alibabacloud-ecs-troubleshoot-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.