Code Audit
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
理解 LeoAI Java/PHP WebShell 与 Java 内存马生成链路,根据用户本次选择的通信、伪装、兼容性和混淆参数生成独立制品。用户要求生成、变体生成、调整兼容性或排查 Shell 无法连接时使用;始终通过 ShellGeneratorTools 完成确定性生成与结果交付。
$ npx skills add cha0upup/LeoAI --skill shell-obfuscation -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cha0upup/LeoAI shell-obfuscation --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .claude/skills && cp -r skills-src/root/skills/platform/shell-obfuscation .claude/skills/shell-obfuscation && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "shell-obfuscation" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/shell-obfuscation into .claude/skills/shell-obfuscation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shell-obfuscation", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/shell-obfuscationType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cha0upup/LeoAI --skill shell-obfuscation -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cha0upup/LeoAI shell-obfuscation --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .agents/skills && cp -r skills-src/root/skills/platform/shell-obfuscation .agents/skills/shell-obfuscation && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "shell-obfuscation" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/shell-obfuscation into .agents/skills/shell-obfuscation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shell-obfuscation", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cha0upup/LeoAI --skill shell-obfuscation -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cha0upup/LeoAI shell-obfuscation --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/root/skills/platform/shell-obfuscation .cursor/skills/shell-obfuscation && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "shell-obfuscation" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/shell-obfuscation into .cursor/skills/shell-obfuscation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shell-obfuscation", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cha0upup/LeoAI.git --path root/skills/platform/shell-obfuscation--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cha0upup/LeoAI --skill shell-obfuscation -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cha0upup/LeoAI shell-obfuscation --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/root/skills/platform/shell-obfuscation .gemini/skills/shell-obfuscation && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "shell-obfuscation" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/shell-obfuscation into .gemini/skills/shell-obfuscation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shell-obfuscation", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cha0upup/LeoAI shell-obfuscationInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cha0upup/LeoAI --skill shell-obfuscation -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .github/skills && cp -r skills-src/root/skills/platform/shell-obfuscation .github/skills/shell-obfuscation && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "shell-obfuscation" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/shell-obfuscation into .github/skills/shell-obfuscation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shell-obfuscation", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cha0upup/LeoAI --skill shell-obfuscation -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cha0upup/LeoAI shell-obfuscation --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cha0upup/LeoAI.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/root/skills/platform/shell-obfuscation .opencode/skills/shell-obfuscation && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "shell-obfuscation" agent skill from https://github.com/cha0upup/LeoAI/tree/main/root/skills/platform/shell-obfuscation into .opencode/skills/shell-obfuscation/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "shell-obfuscation", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
shell-obfuscation理解 LeoAI Java/PHP WebShell 与 Java 内存马生成链路,根据用户本次选择的通信、伪装、兼容性和混淆参数生成独立制品。用户要求生成、变体生成、调整兼容性或排查 Shell 无法连接时使用;始终通过 ShellGeneratorTools 完成确定性生成与结果交付。
Shell Obfuscation is an agent skill from cha0upup/LeoAI. 理解 LeoAI Java/PHP WebShell 与 Java 内存马生成链路,根据用户本次选择的通信、伪装、兼容性和混淆参数生成独立制品。用户要求生成、变体生成、调整兼容性或排查 Shell 无法连接时使用;始终通过 ShellGeneratorTools 完成确定性生成与结果交付。
Its SKILL.md is about 780 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `manifest.yaml`).
It works with Java and PHP. The repository describes itself as: AI 驱动的后渗透综合管理平台,深度集成 LLM Agent,开箱即用。 The licence is GPL-3.0.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit f821bc2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Shell Obfuscation loads about 776 tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 232 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cha0upup/LeoAI at commit f821bc2, republished under its GPL-3.0 licence (© cha0upup). 232 words, ~776 tokens.
.claude/skills/shell-obfuscation/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Shell 是独立生成的制品,不从平台已有 Puppet 自动继承配置。只有用户明确要求“匹配/复制某个 Puppet”时,才可以查询该指定节点;不得因为平台上只有一个节点、最近操作过某个节点或当前页面选中了节点就读取它。
一次生成由五部分组成:
CoreArtifactStore,AI 仅设计不含 Payload 的 Wrapper 模板。ShellResultStore,工具返回 resultId、元数据和取回按钮。不要手写或转述完整生成代码,不要虚构工具未返回的结果。
getShellGeneratorMeta() 获取协议、Java/Servlet、注入器、Packer 和混淆步骤等合法值。getDisguises() 获取当前可选请求/响应伪装器;不得用 Puppet 查询代替该步骤。request_user_input 询问。Java WebShell 至少确认:http 或 httpchunk;JSP 或 JSPX;obfuscate=true/false;启用默认混淆时不传步骤,只有用户指定步骤时才从元数据中选择并保持顺序。auto;已知 Jakarta 环境时显式使用 jakarta。getShellGeneratorMeta() 和 getDisguises()。request_user_input;调用后停止本轮,等待用户回答。createJavaCoreArtifact(...),只接收 coreArtifactId、哈希和契约元数据;不得请求 Core 字节码或 Base64。getWebShellWrapperContract(...) 查看五个阶段占位符和无 Payload 基线模板。designWebShellWrapper(coreArtifactId, shellType, requirements)。工具内部让 AI 设计外层并验证,成功后只返回 wrapperTemplateId。assembleWebShellWrapper(...),明确传入 obfuscate=true/false;平台再次验证模板后才注入真实 Core 并组装结果。[[shell-result:...]] 取回按钮。Java WebShell 的五个阶段占位符必须各出现一次、独占一行并保持顺序。真实加载、读取、调用和响应代码由平台注入,以保证 LeoCore 单次调用和同一 buffer 数据流;AI 不得展开或改写这些阶段。
getShellGeneratorMeta() 和 getDisguises()。packerCompatibility、packerAvailability 和可用混淆步骤。ClassLoaderJSP 或 DefineClassJSP 时,才调用 mutateJspTemplate(...);其他 Packer 不接受 AI 自定义模板。generateMemoryShell(...),检查兼容性警告并交付取回按钮。getShellGeneratorMeta() 和 getDisguises(),确认 PHP generator 的真实能力。http,应向用户说明而不是查询 Puppet。headerName 与 headerValue 必须同时设置或同时留空;不要在回复中显示 Header 密钥。generatePhpWebShell(...),检查最低版本、运行要求、输出模式和警告后交付结果。只有用户明确给出或选择了目标 Puppet,并明确要求生成结果匹配该节点时,才允许读取该节点配置。读取结果只能服务于这次显式匹配;不能把它变成后续独立生成的默认值。排查“某个已生成 Shell 为什么连不上”时,也只有在用户把该 Shell 与具体 Puppet 建立关联后才比较两者配置。
httpchunk:说明当前只支持 http,等待用户确认后再生成。resultId:不得输出取回按钮或声称生成完成。简洁报告生成类型、用户选择的协议与伪装、关键兼容/混淆参数、警告,以及工具返回的取回按钮。除非用户明确要求匹配 Puppet,否则回复中不应出现目标 Puppet。
© cha0upup, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in root/skills/platform/shell-obfuscation of cha0upup/LeoAI.
Open the folder on GitHubat commit f821bc2
Shell Obfuscation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Shell Obfuscation this skillcha0upup/LeoAI | 312 | — | ~776 | Automated safety check: Pass | GPL-3.0 | |
| Code Audit3stoneBrother/code-audit | 893 | 1 repos | ~2.7k | Automated safety check: Pass | None | |
| Audit SkillsRuoJi6/audit-skills | 1k | — | ~447 | Automated safety check: Pass | None | |
| Skylosduriantaco/skylos | 843 | — | ~581 | Automated safety check: Pass | Apache-2.0 | |
| Insecure Deserialization PlaybookPentesterFlow/agent | 1.4k | — | ~1.7k | Automated safety check: Pass | Apache-2.0 | |
| Skylos Securityduriantaco/skylos | 843 | — | ~545 | Automated safety check: Pass | Apache-2.0 |
3stoneBrother/code-audit
Professional code security audit skill covering 55+ vulnerability types.
RuoJi6/audit-skills
当用户要求审计 Java、.NET 或 PHP 源码/部署产物/反编译产物/安全发现,并需要默认脚本输出目录、报告输出目录、Java/.NET 反编译与反混淆参考、Java 组件 YAML 正则匹配扫描、确认漏洞判定标准、安全 Payload 和 BurpSuite 原始 HTTP 请求包证据时使用。仅用于授权代码审计和防御性安全验证。
duriantaco/skylos
Run, interpret, or modify Skylos safely. An agent skill from duriantaco/skylos.
PentesterFlow/agent
Fingerprints which language or framework produced a serialized blob, then helps build a working gadget chain to test for insecure deserialization.
duriantaco/skylos
Investigate and harden Skylos security behavior. An agent skill from duriantaco/skylos.
warpdotdev/warp
Guides building, debugging and tuning apps on the Claude API and Anthropic SDK, including prompt caching, and migrating code between Claude model versions.
cha0upup/LeoAI
当用户希望在平台侧开发、测试、创建或更新 Disguise 时使用。该 skill 用于生成符合平台约束的 trafficEncodeBody、trafficDecodeBody、headersJson、description 和规范名称,并优先调用 testDisguise 验证 traffic 编解码是否可互逆,再创建或更新 Disguise。
cha0upup/LeoAI
发现当前 Puppet 用户的浏览器 Profile,对书签、历史、Cookie、表单和登录数据库建立一致性副本,将选定制品采集到当前 Agent 工作空间,并使用工作空间命令与文件工具解析为可搜索的结构化报告。当用户要求分析浏览器数据、时间线、访问记录、书签或浏览器制品时使用。
cha0upup/LeoAI
当用户希望在平台侧编写、生成、完善、检查、保存、更新或删除指纹规则时使用。指纹由 NetworkProbe 采集证据,服务侧使用声明式 rule.match 判定。
理解 LeoAI Java/PHP WebShell 与 Java 内存马生成链路,根据用户本次选择的通信、伪装、兼容性和混淆参数生成独立制品。用户要求生成、变体生成、调整兼容性或排查 Shell 无法连接时使用;始终通过 ShellGeneratorTools 完成确定性生成与结果交付。. Shell Obfuscation is an agent skill from cha0upup/LeoAI.
Run `npx skills add cha0upup/LeoAI --skill shell-obfuscation -a claude-code`. Or copy the skill folder (root/skills/platform/shell-obfuscation in cha0upup/LeoAI) into .claude/skills/shell-obfuscation in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cha0upup/LeoAI --skill shell-obfuscation -a codex`. Or copy the skill folder (root/skills/platform/shell-obfuscation in cha0upup/LeoAI) into .agents/skills/shell-obfuscation in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cha0upup/LeoAI --skill shell-obfuscation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/shell-obfuscation, .gemini/skills/shell-obfuscation, .github/skills/shell-obfuscation and .opencode/skills/shell-obfuscation in your project.
SKILL.md names no scripts, command-line tools or credentials: Shell Obfuscation is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Shell Obfuscation is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 776 tokens (SKILL.md is roughly 3.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Shell Obfuscation: Code Audit (3stoneBrother/code-audit, 893 stars), Audit Skills (RuoJi6/audit-skills, 1k stars), Skylos (duriantaco/skylos, 843 stars) and Insecure Deserialization Playbook (PentesterFlow/agent, 1.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cha0upup (a GitHub user) maintains it in cha0upup/LeoAI, which has 312 GitHub stars. The repository holds 4 skills in this directory. The repository was last updated on September 30, 2026.
Source: cha0upup/LeoAI on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.